review-pr-changes

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs legitimate operations using official GitHub CLI tools (gh) and diffstat to facilitate Pull Request reviews. It does not contain any obfuscated commands, hardcoded credentials, or unauthorized network activity.\n- [PROMPT_INJECTION]: The skill processes external data from Pull Request diffs and descriptions, which constitutes an indirect prompt injection surface (Category 8). This is an inherent risk of the code review use case, and the skill's instructions mitigate this by providing a fixed, structured checklist for the agent to follow during the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 09:04 PM