review-loop

Fail

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interpolates the user-provided {PR_NUMBER} directly into a bash command string: bash ~/.claude/scripts/check-pr-reviews.sh {PR_NUMBER}. This pattern is highly susceptible to shell command injection if the input contains shell metacharacters (e.g., ; rm -rf /), as there is no evidence of input validation or sanitization before execution.- [PROMPT_INJECTION]: The skill implements an automated fix loop that ingests data from external, potentially attacker-controlled sources (GitHub PR reviews, inline comments, and issue comments) and feeds them into an agent for code modification.
  • Ingestion points: External data is ingested via gh api calls to pulls/{pr}/reviews, pulls/{pr}/comments, and issues/{pr}/comments as specified in Step 2 and Step 3 of SKILL.md.
  • Boundary markers: Absent. The instructions do not provide delimiters or instructions for the agent to distinguish between valid feedback and malicious commands embedded within comments.
  • Capability inventory: The skill is granted Bash, Edit, and Write capabilities, allowing it to execute arbitrary code or modify the repository based on the instructions it receives from the ingested comments.
  • Sanitization: None. The agent is instructed to directly classify and act upon the content of the body field from the API responses.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 11, 2026, 05:08 PM
Security Audit — agent-trust-hub — review-loop