review-pr

Fail

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands like gh pr diff and git diff to fetch data based on user-supplied identifiers (PR numbers or branch names). There is no evidence of sanitization for these arguments, which can lead to command injection if a user provides an identifier containing shell metacharacters (e.g., ; curl ...).
  • [REMOTE_CODE_EXECUTION]: The lexicant agent is explicitly instructed to verify code syntax and integrity through "inline script execution." Since this agent operates on content from pull requests—which are untrusted external sources—this capability presents a high risk of executing malicious code embedded within the PR diffs.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted code diffs and documentation without sanitization.
  • Ingestion points: Pull request diffs (via gh pr diff), roadmap files (docs/roadmap/), and specification files (docs/specs/).
  • Boundary markers: Not present; the PR diff content is interpolated directly into dossier files used by the AI agents.
  • Capability inventory: The skill possesses file-write capabilities (docs/progress/), shell command execution (gh, git), and the lexicant agent can perform inline script execution.
  • Sanitization: No sanitization or filtering logic is described for the ingested external content.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the GitHub CLI (gh) to download code and repository information from external, remote sources.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 16, 2026, 05:13 PM