review-pull-request

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data (PR title, description, and code diffs) fetched via MCP, which could contain embedded instructions. Ingestion points: PR metadata and code changes are ingested in references/step-2-identify-the-target-pr.md and references/step-3-fetch-the-code-diff.md. Boundary markers: The instructions do not define explicit delimiters or instructions to ignore commands that may be contained within the PR data. Capability inventory: The skill utilizes MCP tools to fetch repository data and has the capability to post comments and annotations back to the PR as described in references/step-10-offer-to-post-review-via-mcp.md. Sanitization: No validation or sanitization of the fetched PR content is mentioned before it is processed by the agent or the sub-skill audits.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 12:46 AM
Security Audit — agent-trust-hub — review-pull-request