interface-review

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions mandate the use of shell commands through the git and gh (GitHub CLI) utilities. These include git merge-base, git blame, git fetch, git show, git grep, and git worktree to manage repository state, fetch remote pull request data, and analyze changed surfaces.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content originating from external pull request metadata and commit history, creating a potential surface for indirect injection.
  • Ingestion points: Pull request titles, bodies, and commit messages are retrieved via gh pr view and commit logs (described in SKILL.md and scope-resolution.md).
  • Boundary markers: The instructions lack explicit directives for the agent to use delimiters or ignore instructions that might be embedded within the PR description or code comments being reviewed.
  • Capability inventory: The agent has the capability to execute shell commands (git, gh) and perform network operations via git fetch to interact with remote repositories.
  • Sanitization: There is no mention of sanitizing or escaping the content of pull requests before the agent interprets it to form interface findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:25 PM
Security Audit — agent-trust-hub — interface-review