babysit-pr
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content from pull requests and reviews, creating an attack surface for indirect prompt injection. This is mitigated by explicit operational boundaries and human oversight.
- Ingestion points: Pull request descriptions, review threads, and originating issues or specifications (SKILL.md).
- Boundary markers: The agent is instructed to record the original goal in one sentence as a 'scope boundary' and disregard bot feedback that deviates from this goal.
- Capability inventory: Capabilities include branch repairs (writing code), rebasing, and external communications such as merging, closing PRs, or posting replies.
- Sanitization: The skill mandates explicit human approval for all external actions and requires the agent to wait for confirmation before performing communicative or destructive actions.
Audit Metadata