review-pr
Fail
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands like
gh pr diffandgit diffto fetch data based on user-supplied identifiers (PR numbers or branch names). There is no evidence of sanitization for these arguments, which can lead to command injection if a user provides an identifier containing shell metacharacters (e.g.,; curl ...). - [REMOTE_CODE_EXECUTION]: The
lexicantagent is explicitly instructed to verify code syntax and integrity through "inline script execution." Since this agent operates on content from pull requests—which are untrusted external sources—this capability presents a high risk of executing malicious code embedded within the PR diffs. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted code diffs and documentation without sanitization.
- Ingestion points: Pull request diffs (via
gh pr diff), roadmap files (docs/roadmap/), and specification files (docs/specs/). - Boundary markers: Not present; the PR diff content is interpolated directly into dossier files used by the AI agents.
- Capability inventory: The skill possesses file-write capabilities (
docs/progress/), shell command execution (gh,git), and thelexicantagent can perform inline script execution. - Sanitization: No sanitization or filtering logic is described for the ingested external content.
- [EXTERNAL_DOWNLOADS]: The skill utilizes the GitHub CLI (
gh) to download code and repository information from external, remote sources.
Recommendations
- AI detected serious security threats
Audit Metadata