fix-coderabbit-review

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (GitHub PR comments) and instructs the agent to implement suggested changes, creating a vulnerability to malicious instructions embedded in review feedback.
  • Ingestion points: The scripts/pr_review.py script fetches review comments from the GitHub API and writes them to local markdown files.
  • Boundary markers: The instructions do not employ explicit delimiters or system-level warnings to distinguish between the skill's instructions and the content of the review comments.
  • Capability inventory: The skill provides the agent with capabilities to modify source code, commit changes via git, and execute testing/linting commands via pnpm and uv.
  • Sanitization: scripts/pr_review.py includes a cleanup_html_text function that performs basic HTML tag removal, but does not sanitize potential natural language prompt injections.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands for repository management and workflow execution.
  • The script scripts/pr_review.py executes git config --get remote.origin.url using subprocess.run to identify the target repository.
  • SKILL.md directs the agent to execute project-specific commands like pnpm run lint, pnpm run typecheck, and pnpm run test, as well as git and gh CLI commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — fix-coderabbit-review