github-pr-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub, which could contain malicious instructions for the agent.
- Ingestion points: The automation fetches pull request metadata, comments, and a complete source code tarball in
scripts/main.py. - Boundary markers: The instructions in
scripts/main.py(_build_review_prompt) use text headers to organize information but lack robust delimiters or specific instructions to ignore embedded commands within the reviewed content. - Capability inventory: In
scripts/main.py, the agent is configured withterminalandfile_editortools and is provided with aGITHUB_PERSONAL_ACCESS_TOKENfrom secrets for publishing reviews. - Sanitization: No sanitization, validation, or filtering of the contents retrieved from the pull requests or the repository files is performed before processing.
- [COMMAND_EXECUTION]: The setup workflow in
SKILL.mdinvolves executing shell commands such ascurl,tar, andpython3to verify credentials, prepare the automation, and register it. - [EXTERNAL_DOWNLOADS]: In
scripts/main.py, the skill fetches repository archives from GitHub's official API (api.github.com) to prepare the workspace for the review agent.
Audit Metadata