github-pr-review
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes and processes code from pull requests, which acts as untrusted external input. This surface is vulnerable to indirect prompt injection, where an attacker could embed instructions in code comments or strings to deceive the reviewing agent.
- Ingestion points: Code files and repository diffs retrieved during the review process.
- Boundary markers: No specific delimiters or "ignore instructions" blocks are defined for the input code data.
- Capability inventory: The skill utilizes
gh apiorcurlto write comments, suggestions, and review statuses back to GitHub (SKILL.md, README.md). - Sanitization: The skill follows best practices by using JSON input files (
--input /tmp/review.json) and quoted HEREDOCs ('EOF') to ensure that comment contents containing special characters do not cause shell injection. - [COMMAND_EXECUTION]: The skill uses standard development tools such as
git,gh,grep,sed,head, andtailto inspect the codebase and prepare the review payload. These commands are necessary for the skill's core functionality. - [EXTERNAL_DOWNLOADS]: The skill communicates with the official GitHub API (
api.github.com) to post review data. This is an interaction with a well-known service required for the skill's purpose.
Audit Metadata