pr-review-guide
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to ingest and analyze external, untrusted data including pull request diffs and prior review comments. This represents a potential surface for indirect prompt injection if the ingested data contains instructions meant to influence the agent's behavior.
- Ingestion points: The agent processes pull request diffs and prior review comments from various authors as specified in the 'Unresolved Review Comments' and 'Line Number Tracking' sections.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the content being analyzed, which could lead the agent to interpret data as instructions.
- Capability inventory: The skill utilizes the GitHub CLI (
gh) andgitto read repository data and post review comments back to the platform. - Sanitization: The instructions do not include requirements for sanitizing or escaping the content of comments before they are posted.
- Command Execution: The skill instructs the agent to use standard development tools such as the GitHub CLI (
gh) andgit. While these tools are used to perform the skill's primary functions, users should ensure the agent operates within a restricted environment to maintain the principle of least privilege.
Audit Metadata