babysit-pr

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content from pull requests and reviews, creating an attack surface for indirect prompt injection. This is mitigated by explicit operational boundaries and human oversight.
  • Ingestion points: Pull request descriptions, review threads, and originating issues or specifications (SKILL.md).
  • Boundary markers: The agent is instructed to record the original goal in one sentence as a 'scope boundary' and disregard bot feedback that deviates from this goal.
  • Capability inventory: Capabilities include branch repairs (writing code), rebasing, and external communications such as merging, closing PRs, or posting replies.
  • Sanitization: The skill mandates explicit human approval for all external actions and requires the agent to wait for confirmation before performing communicative or destructive actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:27 AM
Security Audit — agent-trust-hub — babysit-pr