github-pr-review
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection surface identified.\n
- Ingestion points: Pull Request comments and review bodies (including CodeRabbit blocks) are fetched from the GitHub API and used as instructions in
SKILL.md.\n - Boundary markers: No textual delimiters are used for external content; however, the skill relies on the user to gate all actions.\n
- Capability inventory: The skill has access to shell execution (
gh,git), file system modification, and network access (git push).\n - Sanitization: The workflow explicitly mandates human-in-the-loop confirmation before applying any changes and directs the agent to manually review code for correctness.\n- [COMMAND_EXECUTION]: Dynamic context injection is used in
SKILL.mdto executegh pr viewwhen the skill loads. This command provides real-time PR metadata to the agent. The operation is consistent with the skill's purpose as a development tool and uses controlled parameters.
Audit Metadata