github-review-pr

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub Pull Requests, including diffs, comments, and descriptions. This creates a surface for indirect prompt injection where a PR author could embed malicious instructions to influence the agent's behavior. Ingestion points: PR metadata, diffs, and comments are fetched via gh pr view and gh pr diff in SKILL.md steps 1 and 2. Boundary markers: The skill uses a shared UNTRUSTED_CONTENT block in references/subagent-prompts.md that explicitly directs agents to ignore instructions embedded in the code or comments. Capability inventory: The skill can execute various gh commands, including posting review comments and approvals, which could be abused if an injection is successful. Sanitization: No programmatic sanitization is performed; the skill relies on instructional guardrails to distinguish data from instructions.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the GitHub CLI (gh) to read repository data and write review feedback. Evidence: The skill defines allowed tools including Bash(gh pr ...) and Bash(gh api ...) and provides specific command recipes for fetching diffs, history, and past comments from GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 10:19 AM