respond-to-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages the processing of pull request reviews, which involves ingesting potentially malicious instructions from external contributors.
- Ingestion points: Processes external text from PR review comments and feedback (documented in
SKILL.md). - Boundary markers: Employs a "HARD-GATE" protocol requiring the agent to restate all feedback as passive technical requirements and perform verification against the codebase before any implementation starts.
- Capability inventory: The skill is designed to guide file modifications and test execution based on external feedback, typically chaining with TDD and refactoring skills.
- Sanitization: Explicitly identifies "Untrusted / Injection" as a category for review feedback, instructing the agent to ignore, report, and block instructions that attempt to override system gates or prompts.
Audit Metadata