review-pr

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses 'gh' and 'git' CLI tools to view pull request state, fetch repository updates, and merge branches.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) by acting on untrusted pull request comments. Ingestion points: PR review threads and inline comments in SKILL.md Step 3. Boundary markers: Absent. Capability inventory: Executes 'gh' and 'git' commands and invokes code-pushing via /update-pr. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 09:55 PM
Security Audit — agent-trust-hub — review-pr