review-pr-in-worktree
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external GitHub pull requests, including descriptions, comments, and code diffs, which could contain malicious instructions designed to influence the agent's behavior during the review process.
- Ingestion points: PR metadata and source code are fetched via
gh pr viewandgit fetchas described in SKILL.md. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" markers for the PR content it processes.
- Capability inventory: The skill utilizes shell commands (
git,gh) and triggers the execution of the repository's test suite ("gate") as part of the review. - Sanitization: There is no mention of sanitizing or escaping the PR content before analysis.
- [COMMAND_EXECUTION]: The skill executes various git and GitHub CLI (
gh) commands to manage worktrees and fetch remote data. It also facilitates the execution of the repository's own test scripts ("the gate") on the PR's code. - [EXTERNAL_DOWNLOADS]: The skill downloads metadata and code from GitHub. These network operations target a well-known service for the skill's primary purpose of code review.
Audit Metadata