interface-review
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions mandate the use of shell commands through the
gitandgh(GitHub CLI) utilities. These includegit merge-base,git blame,git fetch,git show,git grep, andgit worktreeto manage repository state, fetch remote pull request data, and analyze changed surfaces. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content originating from external pull request metadata and commit history, creating a potential surface for indirect injection.
- Ingestion points: Pull request titles, bodies, and commit messages are retrieved via
gh pr viewand commit logs (described inSKILL.mdandscope-resolution.md). - Boundary markers: The instructions lack explicit directives for the agent to use delimiters or ignore instructions that might be embedded within the PR description or code comments being reviewed.
- Capability inventory: The agent has the capability to execute shell commands (
git,gh) and perform network operations viagit fetchto interact with remote repositories. - Sanitization: There is no mention of sanitizing or escaping the content of pull requests before the agent interprets it to form interface findings.
Audit Metadata