verify-pr-comments

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses gh and git commands to retrieve repository context and PR comment data. These are used for legitimate functionality related to code review analysis.- [PROMPT_INJECTION]: The skill processes external data (PR comments) which constitutes an indirect prompt injection surface. The instructions focus on verification and reporting, which mitigates the risk of the agent executing malicious instructions found in comments.- [COMMAND_EXECUTION]: The skill uses the ! syntax to automatically fetch the repository name and current branch upon loading. These commands are benign and do not use user-controlled arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 03:18 PM
Security Audit — agent-trust-hub — verify-pr-comments