review-a-pr-and-report
Fail
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to locate and execute shell commands found in files like AGENTS.md, AGENTS_REPO.md, or CI workflows within the target repository. If the repository or pull request is malicious, this leads to the execution of arbitrary attacker-controlled code.
- [COMMAND_EXECUTION]: The agent is tasked with running identified 'gating commands' in the review checkout without a safety filter or predefined list of allowed commands, which can be exploited to run harmful system operations.
- [DYNAMIC_EXECUTION]: The execution flow is determined at runtime by parsing strings from repository files, resulting in the dynamic execution of untrusted input gathered from the codebase under review.
- [INDIRECT_PROMPT_INJECTION]: The skill's behavior is influenced by untrusted data in the repository that determines which commands the agent runs. 1. Ingestion points: PR diffs and repository files like AGENTS.md or package.json. 2. Boundary markers: None defined to isolate or ignore malicious instructions within the repo files. 3. Capability inventory: Full shell command execution via subprocesses to run identified gates. 4. Sanitization: No sanitization or validation of the extracted command strings before execution.
Recommendations
- AI detected serious security threats
Audit Metadata