pr-review
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process pull request diffs and metadata using the
ghcommand-line tool. Since this data is provided by external contributors, it could contain hidden instructions (indirect prompt injection) intended to influence the agent's review or trick it into approving malicious changes. - Ingestion points: Untrusted data enters the agent context via the
gh pr diffandgh pr viewcommands inSKILL.mdandreferences/strict.md. - Boundary markers: There are no explicit instructions or delimiters telling the agent to treat the diff content as data only and to ignore any natural language instructions found within the code or comments.
- Capability inventory: The skill provides the agent with the authority to modify repository state by approving PRs using
gh pr review --approve(found inreferences/light.mdandreferences/strict.md). - Sanitization: The skill does not implement sanitization or filtering of the PR content before analysis.
- [COMMAND_EXECUTION]: The skill uses the standard GitHub CLI (
gh) to perform its primary functions. While these commands are necessary for the skill's purpose, they allow the agent to interact with external repositories and submit reviews. - Evidence: Commands include
gh pr diff,gh pr view, andgh pr reviewfound acrossSKILL.md,references/light.md, andreferences/strict.md.
Audit Metadata