git-pr-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate instructions for performing code reviews. The use of git diff and the provided checklist are consistent with the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external code from pull requests, which presents a surface for indirect prompt injection. * Ingestion points: Code diffs retrieved from git repositories (SKILL.md). * Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore embedded instructions' markers when the agent processes the diff content. * Capability inventory: The skill is granted access to the Bash, Read, Grep, and Glob tools (SKILL.md). * Sanitization: There is no requirement for the agent to sanitize or filter the content of the files being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — git-pr-reviewer