pull-requests
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use various shell commands and repository-specific scripts to manage Pull Requests.
- Evidence: Directs the usage of
gitfor rebasing and pushing,makefor local testing, andghfor commenting on PRs. - Evidence: Invokes multiple repository-specific scripts in the
./scripts/directory for review management and status checking. - Evidence: Instructs the agent to access environment variables via bash to populate attribution footers.
- [INDIRECT_PROMPT_INJECTION]: The skill processes instructions from an external automated reviewer, creating a potential surface for indirect injection.
- Ingestion points: Reads review comments from the Codex system using
./scripts/check_codex_comments.sh. - Boundary markers: No specific delimiters or "ignore warnings" are defined for the comment content.
- Capability inventory: The agent has capabilities to push code changes (
git push) and post comments (gh pr comment). - Sanitization: There are no explicit instructions for sanitizing or filtering the external comment content.
Audit Metadata