review-pr

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process significant amounts of untrusted data from GitHub PRs, including PR descriptions, author replies, commit messages, and external linked-PR content (stack/bundle context).
  • Ingestion points: SKILL.md specifies reading pr-url content, PR-description, linked-PR context, and author replies on existing threads. references/MANIFEST_MODE.md also ingests a manifest file from a user-provided path.
  • Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" guards for the data passed to the reviewer fleet or holistic pass.
  • Capability inventory: The skill uses review-code, review-pr-thread-verify, review-pr-holistic, and review-pr-judgment sub-skills. In manifest mode, it performs tests, builds, greps against the PR head, which involves executing code found in the PR context.
  • Sanitization: No explicit sanitization of PR descriptions or linked content is mentioned before it is forwarded to the LLM-driven reviewer fleet.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 08:34 PM
Security Audit — agent-trust-hub — review-pr