address-pr-review

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git and gh (GitHub CLI) to fetch pull request data, apply changes, and push updates to the remote repository. This behavior is expected and appropriate for its stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted pull request comments, which serves as an ingestion point for potentially malicious instructions.
  • Ingestion points: Reviewer comments are fetched using gh api in SKILL.md (Step 1).
  • Boundary markers: Absent. The instructions do not specify any delimiters to isolate the untrusted data from the agent's internal logic.
  • Capability inventory: The skill has the capability to modify code, create commits, and push changes to a repository (SKILL.md Steps 4, 5, and 7).
  • Sanitization: Absent. There is no logic for validating or filtering the content of the comments before they are analyzed and acted upon.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — address-pr-review