pr-feedback-quality-gate
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns such as obfuscation, credential exfiltration, or unauthorized remote code execution were detected. The instructions align with standard software engineering practices for handling PR reviews.
- [COMMAND_EXECUTION]: The skill triggers local repository commands such as
pnpm guard, builds, and tests. These are restricted to the local environment for the purpose of validating fixes before they are committed. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data in the form of PR review comments and feedback.
- Ingestion points: Pull Request comments, review history, and check results.
- Boundary markers: The instructions explicitly state to treat cross-review as 'evidence, not authority' and to reject suggestions that conflict with safety.
- Capability inventory: File system access for fixes, execution of repository validation tools (
pnpm), and git write commands (git commit,git push). - Sanitization: The skill relies on manual validation and automated gates (
pnpm guard) rather than explicit input sanitization of the comments.
Audit Metadata