review-pr
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process significant amounts of untrusted data from GitHub PRs, including PR descriptions, author replies, commit messages, and external linked-PR content (stack/bundle context).
- Ingestion points:
SKILL.mdspecifies readingpr-urlcontent,PR-description,linked-PR context, and author replies on existing threads.references/MANIFEST_MODE.mdalso ingests a manifest file from a user-provided path. - Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" guards for the data passed to the reviewer fleet or holistic pass.
- Capability inventory: The skill uses
review-code,review-pr-thread-verify,review-pr-holistic, andreview-pr-judgmentsub-skills. In manifest mode, it performstests, builds, grepsagainst the PR head, which involves executing code found in the PR context. - Sanitization: No explicit sanitization of PR descriptions or linked content is mentioned before it is forwarded to the LLM-driven reviewer fleet.
Audit Metadata