github-review-pr
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub Pull Requests, including diffs, comments, and descriptions. This creates a surface for indirect prompt injection where a PR author could embed malicious instructions to influence the agent's behavior. Ingestion points: PR metadata, diffs, and comments are fetched via
gh pr viewandgh pr diffinSKILL.mdsteps 1 and 2. Boundary markers: The skill uses a sharedUNTRUSTED_CONTENTblock inreferences/subagent-prompts.mdthat explicitly directs agents to ignore instructions embedded in the code or comments. Capability inventory: The skill can execute variousghcommands, including posting review comments and approvals, which could be abused if an injection is successful. Sanitization: No programmatic sanitization is performed; the skill relies on instructional guardrails to distinguish data from instructions. - [COMMAND_EXECUTION]: The skill makes extensive use of the GitHub CLI (
gh) to read repository data and write review feedback. Evidence: The skill defines allowed tools includingBash(gh pr ...)andBash(gh api ...)and provides specific command recipes for fetching diffs, history, and past comments from GitHub.
Audit Metadata