address-pr-review
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
gitandgh(GitHub CLI) to fetch pull request data, apply changes, and push updates to the remote repository. This behavior is expected and appropriate for its stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted pull request comments, which serves as an ingestion point for potentially malicious instructions.
- Ingestion points: Reviewer comments are fetched using
gh apiinSKILL.md(Step 1). - Boundary markers: Absent. The instructions do not specify any delimiters to isolate the untrusted data from the agent's internal logic.
- Capability inventory: The skill has the capability to modify code, create commits, and push changes to a repository (
SKILL.mdSteps 4, 5, and 7). - Sanitization: Absent. There is no logic for validating or filtering the content of the comments before they are analyzed and acted upon.
Audit Metadata