review-pr
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub PR metadata, diffs, and Linear tickets. This surface is well-mitigated through defense-in-depth strategies.
- Ingestion points: Untrusted content enters via
gh pr view,gh pr diff, and the Linear issue retrieval tool. - Boundary markers: The orchestration logic uses a 'Review Charter' and 'Review Context' to delineate trusted instructions from untrusted PR data, explicitly directing agents to prioritize grounding tickets over PR body claims.
- Capability inventory: The skill possesses capabilities to execute code (via a sandboxed CLI) and write files (to a local triage directory). All PR code execution is strictly routed through an isolated sandbox environment (gVisor or Docker VM).
- Sanitization: A specific sanitization routine is implemented for issue reproduction commands, rejecting shell metacharacters such as backticks, semicolons, and pipes before the command is passed to the sandbox.
- [COMMAND_EXECUTION]: The skill uses various shell tools (
gh,git,jq,sed) for orchestration. A verification system for agent findings usessedto check line numbers against the diff; this logic includes a robust numeric validation branch to prevent command injection from agent-authored content. - [EXTERNAL_DOWNLOADS]: The skill fetches data from GitHub and Linear APIs. These are well-known technology services, and the interactions are consistent with the skill's primary purpose of code review.
- [SAFE]: The skill demonstrates a high level of security awareness, employing sandboxing for untrusted code and rigorous validation for all data flowing from sub-agents to the host environment.
Audit Metadata