walk-pr
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill dynamically generates a self-contained HTML file in the host's temporary directory to facilitate a visual PR walkthrough.- [EXTERNAL_DOWNLOADS]: The generated HTML artifact references third-party libraries (diff2html and highlight.js) from the JSDelivr CDN. These are well-known services used for rendering code diffs.- [COMMAND_EXECUTION]: The skill uses system-level commands (xdg-open, open, or start) to launch the generated HTML interface in the user's default web browser. It also utilizes Git and GitHub CLI (gh) for repository operations.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PR diffs and design documentation which could contain malicious instructions.
- Ingestion points: PR diffs and repository design documents provided as arguments or fetched via CLI tools.
- Boundary markers: No explicit instruction-isolation delimiters are defined for the processed diff content.
- Capability inventory: The skill can write to local files, execute browser launchers, and post data to GitHub.
- Sanitization: The reference implementation uses basic tag stripping for UI labels, but renders core content using innerHTML, which may be susceptible to XSS if the PR content contains malicious HTML.
Audit Metadata