check-pr
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external GitHub Pull Requests, including descriptions and human-authored review comments.
- Ingestion points: PR metadata, descriptions, and review threads fetched via the provided PR URL.
- Boundary markers: Absent in the data ingestion phase, although the instructions include explicit prohibitions for the agent against executing content found in PR bodies.
- Capability inventory: The skill can generate directives for shell execution (
bash sleep), CI re-triggering, and GitHub API interactions (replies, resolving threads). - Sanitization: None specified for the PR content included in the
Context:field of the output. - [PROMPT_INJECTION]: The
Steeringinput is defined as an unstructured "plain-English overlay" that can override standard gates and logic. - Evidence: The instructions state "Steering — optional plain-English overlay (extra gates... wait-duration overrides, custom bot routing). Parse with judgment; no schema." This allows a user to provide instructions that may conflict with the core safety or operational guidelines of the skill.
- [COMMAND_EXECUTION]: The skill explicitly generates shell commands for the caller to execute as part of its standard workflow.
- Evidence: The
bash sleep <N>; reinvokedirective is a literal command vocabulary token intended to be executed by the calling environment. While the command itself is low-risk, the design pattern of generating executable shell strings is a notable capability.
Audit Metadata