pr-feedback-quality-gate

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns such as obfuscation, credential exfiltration, or unauthorized remote code execution were detected. The instructions align with standard software engineering practices for handling PR reviews.
  • [COMMAND_EXECUTION]: The skill triggers local repository commands such as pnpm guard, builds, and tests. These are restricted to the local environment for the purpose of validating fixes before they are committed.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data in the form of PR review comments and feedback.
  • Ingestion points: Pull Request comments, review history, and check results.
  • Boundary markers: The instructions explicitly state to treat cross-review as 'evidence, not authority' and to reject suggestions that conflict with safety.
  • Capability inventory: File system access for fixes, execution of repository validation tools (pnpm), and git write commands (git commit, git push).
  • Sanitization: The skill relies on manual validation and automated gates (pnpm guard) rather than explicit input sanitization of the comments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — pr-feedback-quality-gate