pr-babysitter
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by fetching all PR review threads, comments, and issue comments via
scripts/fetch-comments.sh. - Ingestion points: Data enters the agent context through the output of
scripts/fetch-comments.shin theComment Triage Workflow, which pages through and returns all GitHub PR activities. - Boundary markers: The skill uses classification logic in
references/bot-patterns.mdand a fix plan template inreferences/fix-plan-template.mdto structure the triaged data, although it lacks strict delimiters to fully isolate external data from instructions. - Capability inventory: The skill possesses extensive capabilities including executing project-defined scripts (lint, test, build) as described in
references/verification-gate.md, and performing repository mutations likegit pushandgh pr merge. - Sanitization: The
fetch-comments.shscript employs astrip_markupfunction usingjqto remove HTML comments,<details>blocks, and common bot boilerplate from fetched content bodies. - [COMMAND_EXECUTION]: The
references/verification-gate.mdcomponent instructs the agent to dynamically detect and execute shell commands defined in the project's task runner (e.g.,package.jsonscripts,Makefiletargets). This provides an execution vector for scripts that might be modified by the agent or an external contributor. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to interact with CI/CD platforms and well-known services.
- Evidence:
references/ci-platforms.mdutilizescurlto interact with the Buildkite REST API (api.buildkite.com) for log retrieval and build retries. These operations target well-known services and align with the skill's primary purpose.
Audit Metadata