coderabbit

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions provide a command to download and execute an installation script from the official domain (https://cli.coderabbit.ai/install.sh | sh). This is documented for setup and originates from the recognized domain of the tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a configuration surface in references/configuration.md where files like CLAUDE.md are automatically ingested to guide AI behavior, potentially allowing malicious content in those files to influence the agent. 1. Ingestion points: Guideline files like CLAUDE.md. 2. Boundary markers: None identified. 3. Capability inventory: The tool executes CLI commands and transmits data. 4. Sanitization: Not specified.
  • [COMMAND_EXECUTION]: The skill details various CLI operations including authentication and local review triggers.
  • [EXTERNAL_DOWNLOADS]: The skill references the download of installation scripts and binary updates from external sources.
Recommendations
  • HIGH: Downloads and executes remote code from: https://cli.coderabbit.ai/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 03:55 PM
Security Audit — agent-trust-hub — coderabbit