repos-pull-request-review

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
  • Ingestion points: Fetches PR titles, descriptions, code diffs, discussion threads, and work item details via Azure DevOps REST APIs (detailed in rules 1, 2, and 3).
  • Boundary markers: The skill requires the agent to present its generated review comments to the user for verification before posting them (Rule 4).
  • Capability inventory: Executes curl (network GET/POST/PUT/PATCH), git diff (local file analysis), and local file writes for temporary diff storage (Rule 2.4).
  • Sanitization: Implements URL encoding for project and repository names in API paths and query strings to prevent command or path traversal issues.
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands to perform its core functions.
  • Evidence: Uses curl for API interactions and git diff for comparing code versions. While these follow predefined templates, they involve user-controlled variables like project names and file paths.
  • [SAFE]: The skill demonstrates security awareness regarding credential management.
  • Evidence: It strictly manages tokens through environment variables, explicitly forbids printing them or writing them to disk, and warns the user about token expiration or invalidity. It also implements a human-in-the-loop requirement for all write actions (Rule 4).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 04:39 AM