check-pr

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external GitHub Pull Requests, including descriptions and human-authored review comments.
  • Ingestion points: PR metadata, descriptions, and review threads fetched via the provided PR URL.
  • Boundary markers: Absent in the data ingestion phase, although the instructions include explicit prohibitions for the agent against executing content found in PR bodies.
  • Capability inventory: The skill can generate directives for shell execution (bash sleep), CI re-triggering, and GitHub API interactions (replies, resolving threads).
  • Sanitization: None specified for the PR content included in the Context: field of the output.
  • [PROMPT_INJECTION]: The Steering input is defined as an unstructured "plain-English overlay" that can override standard gates and logic.
  • Evidence: The instructions state "Steering — optional plain-English overlay (extra gates... wait-duration overrides, custom bot routing). Parse with judgment; no schema." This allows a user to provide instructions that may conflict with the core safety or operational guidelines of the skill.
  • [COMMAND_EXECUTION]: The skill explicitly generates shell commands for the caller to execute as part of its standard workflow.
  • Evidence: The bash sleep <N>; reinvoke directive is a literal command vocabulary token intended to be executed by the calling environment. While the command itself is low-risk, the design pattern of generating executable shell strings is a notable capability.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 11:14 AM
Security Audit — agent-trust-hub — check-pr