github-pr-review

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection surface identified.\n
  • Ingestion points: Pull Request comments and review bodies (including CodeRabbit blocks) are fetched from the GitHub API and used as instructions in SKILL.md.\n
  • Boundary markers: No textual delimiters are used for external content; however, the skill relies on the user to gate all actions.\n
  • Capability inventory: The skill has access to shell execution (gh, git), file system modification, and network access (git push).\n
  • Sanitization: The workflow explicitly mandates human-in-the-loop confirmation before applying any changes and directs the agent to manually review code for correctness.\n- [COMMAND_EXECUTION]: Dynamic context injection is used in SKILL.md to execute gh pr view when the skill loads. This command provides real-time PR metadata to the agent. The operation is consistent with the skill's purpose as a development tool and uses controlled parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — github-pr-review