fix-coderabbit-review
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified. The skill performs expected repository maintenance tasks related to PR remediation.
- [COMMAND_EXECUTION]: The skill utilizes local scripts (
pr-review.ts,resolve_pr_issues.sh) and standard utilities likegit,pnpm, andghto manage the workflow. These operations are transparent and necessary for the stated functionality. - [DATA_EXPOSURE]: The skill interacts with the GitHub API using an environment-provided
GITHUB_TOKEN. It reads repository configuration and PR comments, but data remains within the local environment and the official GitHub API. - [PROMPT_INJECTION]: The workflow involves processing external content (PR comments), which is a surface for indirect prompt injection. The skill mitigates this risk by instructing the agent to perform technical triage and validation for every issue instead of applying changes blindly. Evidence: (1) Ingestion:
scripts/pr-review.tsfetches PR comments via GitHub API. (2) Boundaries:SKILL.mdrequires technical validation and triage. (3) Capabilities:git commit,pnpm test, andgh apicalls. (4) Sanitization: External content is rendered into markdown files for review.
Audit Metadata