review-pr-in-lane
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies when a Pull Request is ready for review by monitoring GitHub issue comments and notifications for specific trigger strings. Because it ingests untrusted data from these external sources to determine the PR number and initiate a review workflow, it is susceptible to indirect prompt injection.
- Ingestion points: GitHub issue comments (polled via the Monitor tool) and agent notifications (via ReadNotifications).
- Boundary markers: The skill does not define explicit delimiters or 'ignore' instructions for the data ingested from comments.
- Capability inventory: The agent uses the GitHub CLI (gh pr view) to interact with repositories and initiates a worktree-based code review process involving file system access.
- Sanitization: There is no evidence of validation or sanitization for the PR number or repository details extracted from the external comments before they are used in subsequent tools.
Audit Metadata