fix-coderabbit-review
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (GitHub PR comments) and instructs the agent to implement suggested changes, creating a vulnerability to malicious instructions embedded in review feedback.
- Ingestion points: The
scripts/pr_review.pyscript fetches review comments from the GitHub API and writes them to local markdown files. - Boundary markers: The instructions do not employ explicit delimiters or system-level warnings to distinguish between the skill's instructions and the content of the review comments.
- Capability inventory: The skill provides the agent with capabilities to modify source code, commit changes via
git, and execute testing/linting commands viapnpmanduv. - Sanitization:
scripts/pr_review.pyincludes acleanup_html_textfunction that performs basic HTML tag removal, but does not sanitize potential natural language prompt injections. - [COMMAND_EXECUTION]: The skill utilizes shell commands for repository management and workflow execution.
- The script
scripts/pr_review.pyexecutesgit config --get remote.origin.urlusingsubprocess.runto identify the target repository. SKILL.mddirects the agent to execute project-specific commands likepnpm run lint,pnpm run typecheck, andpnpm run test, as well asgitandghCLI commands.
Audit Metadata