repos-pull-request-review
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
- Ingestion points: Fetches PR titles, descriptions, code diffs, discussion threads, and work item details via Azure DevOps REST APIs (detailed in rules 1, 2, and 3).
- Boundary markers: The skill requires the agent to present its generated review comments to the user for verification before posting them (Rule 4).
- Capability inventory: Executes
curl(network GET/POST/PUT/PATCH),git diff(local file analysis), and local file writes for temporary diff storage (Rule 2.4). - Sanitization: Implements URL encoding for project and repository names in API paths and query strings to prevent command or path traversal issues.
- [COMMAND_EXECUTION]: The skill relies on executing shell commands to perform its core functions.
- Evidence: Uses
curlfor API interactions andgit difffor comparing code versions. While these follow predefined templates, they involve user-controlled variables like project names and file paths. - [SAFE]: The skill demonstrates security awareness regarding credential management.
- Evidence: It strictly manages tokens through environment variables, explicitly forbids printing them or writing them to disk, and warns the user about token expiration or invalidity. It also implements a human-in-the-loop requirement for all write actions (Rule 4).
Audit Metadata