review-pull-request
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data (PR title, description, and code diffs) fetched via MCP, which could contain embedded instructions. Ingestion points: PR metadata and code changes are ingested in
references/step-2-identify-the-target-pr.mdandreferences/step-3-fetch-the-code-diff.md. Boundary markers: The instructions do not define explicit delimiters or instructions to ignore commands that may be contained within the PR data. Capability inventory: The skill utilizes MCP tools to fetch repository data and has the capability to post comments and annotations back to the PR as described inreferences/step-10-offer-to-post-review-via-mcp.md. Sanitization: No validation or sanitization of the fetched PR content is mentioned before it is processed by the agent or the sub-skill audits.
Audit Metadata