babysit-pr

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to monitor and automatically respond to pull request comments and CI check results.
  • Ingestion points: The agent consumes data from external pull request comments and CI logs as described in SKILL.md.
  • Boundary markers: There are no defined boundary markers or specific instructions to treat external comment content exclusively as data rather than potential instructions.
  • Capability inventory: The agent is instructed to modify code, post comments on behalf of the user, and merge pull requests based on these external inputs.
  • Sanitization: No input sanitization or validation of the external content is prescribed, although the instructions include a requirement to verify findings against the source code before acting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 11:48 AM
Security Audit — agent-trust-hub — babysit-pr