pr-babysitter

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by fetching all PR review threads, comments, and issue comments via scripts/fetch-comments.sh.
  • Ingestion points: Data enters the agent context through the output of scripts/fetch-comments.sh in the Comment Triage Workflow, which pages through and returns all GitHub PR activities.
  • Boundary markers: The skill uses classification logic in references/bot-patterns.md and a fix plan template in references/fix-plan-template.md to structure the triaged data, although it lacks strict delimiters to fully isolate external data from instructions.
  • Capability inventory: The skill possesses extensive capabilities including executing project-defined scripts (lint, test, build) as described in references/verification-gate.md, and performing repository mutations like git push and gh pr merge.
  • Sanitization: The fetch-comments.sh script employs a strip_markup function using jq to remove HTML comments, <details> blocks, and common bot boilerplate from fetched content bodies.
  • [COMMAND_EXECUTION]: The references/verification-gate.md component instructs the agent to dynamically detect and execute shell commands defined in the project's task runner (e.g., package.json scripts, Makefile targets). This provides an execution vector for scripts that might be modified by the agent or an external contributor.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to interact with CI/CD platforms and well-known services.
  • Evidence: references/ci-platforms.md utilizes curl to interact with the Buildkite REST API (api.buildkite.com) for log retrieval and build retries. These operations target well-known services and align with the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:50 PM
Security Audit — agent-trust-hub — pr-babysitter