coderabbit
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions provide a command to download and execute an installation script from the official domain (https://cli.coderabbit.ai/install.sh | sh). This is documented for setup and originates from the recognized domain of the tool.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a configuration surface in references/configuration.md where files like CLAUDE.md are automatically ingested to guide AI behavior, potentially allowing malicious content in those files to influence the agent. 1. Ingestion points: Guideline files like CLAUDE.md. 2. Boundary markers: None identified. 3. Capability inventory: The tool executes CLI commands and transmits data. 4. Sanitization: Not specified.
- [COMMAND_EXECUTION]: The skill details various CLI operations including authentication and local review triggers.
- [EXTERNAL_DOWNLOADS]: The skill references the download of installation scripts and binary updates from external sources.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.coderabbit.ai/install.sh - DO NOT USE without thorough review
Audit Metadata