fix-coderabbit-review

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified. The skill performs expected repository maintenance tasks related to PR remediation.
  • [COMMAND_EXECUTION]: The skill utilizes local scripts (pr-review.ts, resolve_pr_issues.sh) and standard utilities like git, pnpm, and gh to manage the workflow. These operations are transparent and necessary for the stated functionality.
  • [DATA_EXPOSURE]: The skill interacts with the GitHub API using an environment-provided GITHUB_TOKEN. It reads repository configuration and PR comments, but data remains within the local environment and the official GitHub API.
  • [PROMPT_INJECTION]: The workflow involves processing external content (PR comments), which is a surface for indirect prompt injection. The skill mitigates this risk by instructing the agent to perform technical triage and validation for every issue instead of applying changes blindly. Evidence: (1) Ingestion: scripts/pr-review.ts fetches PR comments via GitHub API. (2) Boundaries: SKILL.md requires technical validation and triage. (3) Capabilities: git commit, pnpm test, and gh api calls. (4) Sanitization: External content is rendered into markdown files for review.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — fix-coderabbit-review