code-review-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources such as pull request descriptions, diffs, and comments.
  • Ingestion points: The workflow utilizes gh pr view, gh pr diff, and git diff to pull external content into the agent's context as shown in SKILL.md.
  • Boundary markers: There are no instructions or delimiters defined to help the agent distinguish between the skill's instructions and the untrusted content being reviewed.
  • Capability inventory: The agent has access to the Bash tool with permissions to run git, gh, npm, npx, pytest, go, and cargo as specified in the allowed-tools section of SKILL.md.
  • Sanitization: The skill lacks any instructions for sanitizing or validating external content before it is processed or used in shell commands.
  • [REMOTE_CODE_EXECUTION]: In Step 7 ("Verify claims you can check"), the skill instructs the agent to run gh pr checkout followed by npm test, npm run typecheck, and npm run lint. This creates an execution path for arbitrary code defined in the pull request's package.json or other configuration files, which could be exploited by a malicious contributor to execute code in the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:03 PM
Security Audit — agent-trust-hub — code-review-workflow