pr-review-prep
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates on local repository data to generate documentation artifacts. No malicious patterns such as prompt injection, obfuscation, or persistence mechanisms were detected.
- [DATA_EXFILTRATION]: The skill contains explicit safeguards against data exfiltration. The 'Operating Contract' and 'Tool Rules' strictly forbid pushing to remote repositories, calling hosting APIs, or exposing secrets. Network operations are intentionally excluded from the skill's scope.
- [PROMPT_INJECTION]: The instructions do not contain patterns attempting to bypass safety filters or override agent constraints. Instead, the skill enforces high-rigor rules, requiring the agent to base all claims on observed evidence and explicitly flagging security-sensitive areas for human review rather than claiming they are safe.
- [COMMAND_EXECUTION]: The skill is permitted to inspect repository state (diffs, logs, templates) and write a single local file (
PR_BODY.md) only upon explicit user request. This follows the principle of least privilege and requires verification of the resulting file diff. - [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted data in the form of branch diffs, it includes robust mitigation strategies:
- Ingestion points: Branch diffs, project files, and repository logs.
- Boundary markers: Instructions explicitly require separating inferred guidance from facts and state that security/auth areas must be flagged for focus, not verified as safe.
- Capability inventory: Local file/diff reading and single-file local writing; no network or remote execution capabilities.
- Sanitization: The skill mandates reporting assumptions and verification gaps, preventing the agent from being misled by embedded instructions in the diff data.
Audit Metadata