pr-review-guide

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and analyze external, untrusted data including pull request diffs and prior review comments. This represents a potential surface for indirect prompt injection if the ingested data contains instructions meant to influence the agent's behavior.
  • Ingestion points: The agent processes pull request diffs and prior review comments from various authors as specified in the 'Unresolved Review Comments' and 'Line Number Tracking' sections.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the content being analyzed, which could lead the agent to interpret data as instructions.
  • Capability inventory: The skill utilizes the GitHub CLI (gh) and git to read repository data and post review comments back to the platform.
  • Sanitization: The instructions do not include requirements for sanitizing or escaping the content of comments before they are posted.
  • Command Execution: The skill instructs the agent to use standard development tools such as the GitHub CLI (gh) and git. While these tools are used to perform the skill's primary functions, users should ensure the agent operates within a restricted environment to maintain the principle of least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:03 PM
Security Audit — agent-trust-hub — pr-review-guide