babysit-pr
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to monitor and automatically respond to pull request comments and CI check results.
- Ingestion points: The agent consumes data from external pull request comments and CI logs as described in SKILL.md.
- Boundary markers: There are no defined boundary markers or specific instructions to treat external comment content exclusively as data rather than potential instructions.
- Capability inventory: The agent is instructed to modify code, post comments on behalf of the user, and merge pull requests based on these external inputs.
- Sanitization: No input sanitization or validation of the external content is prescribed, although the instructions include a requirement to verify findings against the source code before acting.
Audit Metadata