review-validation
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill processes untrusted data from pull request metadata, descriptions, and repository files, which could potentially contain malicious instructions intended to influence the validation process.
- Ingestion Points: Data enters the agent context through
args.prBody,args.prTemplate, and repository content retrieved via theread_repo_filetool. - Boundary Markers: The skill includes a 'Security' section that explicitly instructs the agent to treat pull request content as untrusted and to disregard any instructions embedded within it.
- Capability Inventory: The skill is equipped with tools to read repository files (
read_repo_file), search the codebase (search_repo), and submit validation results (submit_review_validation). - Sanitization: The skill relies on natural language instructions to maintain boundaries rather than programmatic sanitization of the input data.
Audit Metadata