setup-pr-review
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices by explicitly instructing the agent not to handle or ask for API keys. It directs the user to manually configure the
LLM_API_KEYin GitHub's native secrets management system. - [SAFE]: All external resources, including the workflow templates and the composite action (
OpenHands/extensions/plugins/pr-review), originate from the official repositories and documentation domains of the skill's author (OpenHands). - [SAFE]: The skill uses standard GitHub Action configuration patterns and does not attempt to execute arbitrary code or access sensitive local files. Its primary function is file generation based on predefined user preferences.
Audit Metadata