review-loop
Fail
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill interpolates the user-provided
{PR_NUMBER}directly into a bash command string:bash ~/.claude/scripts/check-pr-reviews.sh {PR_NUMBER}. This pattern is highly susceptible to shell command injection if the input contains shell metacharacters (e.g.,; rm -rf /), as there is no evidence of input validation or sanitization before execution.- [PROMPT_INJECTION]: The skill implements an automated fix loop that ingests data from external, potentially attacker-controlled sources (GitHub PR reviews, inline comments, and issue comments) and feeds them into an agent for code modification. - Ingestion points: External data is ingested via
gh apicalls topulls/{pr}/reviews,pulls/{pr}/comments, andissues/{pr}/commentsas specified in Step 2 and Step 3 ofSKILL.md. - Boundary markers: Absent. The instructions do not provide delimiters or instructions for the agent to distinguish between valid feedback and malicious commands embedded within comments.
- Capability inventory: The skill is granted
Bash,Edit, andWritecapabilities, allowing it to execute arbitrary code or modify the repository based on the instructions it receives from the ingested comments. - Sanitization: None. The agent is instructed to directly classify and act upon the content of the
bodyfield from the API responses.
Recommendations
- AI detected serious security threats
Audit Metadata