coderabbit
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains instructions for installing the CodeRabbit CLI using
curl -fsSL https://cli.coderabbit.ai/install.sh | sh. This URL points to the official distribution domain of CodeRabbit, which is a well-known service in the AI code review space, making the external reference safe. - [COMMAND_EXECUTION]: The helper script
scripts/run_coderabbit.pyexecutes localgitandcoderabbitcommands using thesubprocessmodule. These invocations use list-based arguments without theshell=Trueparameter, which prevents shell injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection because it ingests and processes untrusted data from the user's repository (source code, configuration files like
.coderabbit.yaml, and documentation likeclaude.md). - Ingestion points: Repository files analyzed by the CLI and the subsequent report written to
coderabbit-report.txt. - Boundary markers: None identified to separate review output from agent instructions.
- Capability inventory:
subprocesscalls inscripts/run_coderabbit.pyto execute local binaries. - Sanitization: No specific sanitization or filtering of the tool's output is performed before it is provided to the agent.
Audit Metadata