github-pr-review

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes and processes code from pull requests, which acts as untrusted external input. This surface is vulnerable to indirect prompt injection, where an attacker could embed instructions in code comments or strings to deceive the reviewing agent.
  • Ingestion points: Code files and repository diffs retrieved during the review process.
  • Boundary markers: No specific delimiters or "ignore instructions" blocks are defined for the input code data.
  • Capability inventory: The skill utilizes gh api or curl to write comments, suggestions, and review statuses back to GitHub (SKILL.md, README.md).
  • Sanitization: The skill follows best practices by using JSON input files (--input /tmp/review.json) and quoted HEREDOCs ('EOF') to ensure that comment contents containing special characters do not cause shell injection.
  • [COMMAND_EXECUTION]: The skill uses standard development tools such as git, gh, grep, sed, head, and tail to inspect the codebase and prepare the review payload. These commands are necessary for the skill's core functionality.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the official GitHub API (api.github.com) to post review data. This is an interaction with a well-known service required for the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — github-pr-review