pr-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to review untrusted code diffs and repository files. It specifically instructs the agent to load and follow rules defined in files like
REVIEW.md,AGENTS.md, andCLAUDE.mdfound within the target repository. This creates a surface for indirect prompt injection where a malicious PR could include instructions to subvert the review process.\n - Ingestion points: The agent reads PR diffs via
git diffandgh pr diff, and context files likeREVIEW.mdandCLAUDE.md.\n - Capability inventory: The skill has access to shell commands (
git,gh,grep,cat) and can potentially run external AI CLI tools.\n - Boundary markers: The instructions do not define clear boundaries or 'ignore' directives for content processed from the PR.\n
- Sanitization: There is no explicit sanitization of the content read from the PR before it is processed by the AI.\n- [COMMAND_EXECUTION]: The skill makes extensive use of local shell commands to gather context and perform the review. These include
git,gh,grep, andcat. While these are standard for this type of tool, the skill's reliance on them to process untrusted input increases the potential impact of other vulnerabilities.\n- [DYNAMIC_EXECUTION]: The skill suggests an optional 'second opinion' pass using external CLI tools likecodex execordroid exec. While the skill describes this as a read-only pass, it involves passing the diff content to another execution environment, which could lead to unintended code execution if the external tools are not properly isolated.
Audit Metadata