code-review-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources such as pull request descriptions, diffs, and comments.
- Ingestion points: The workflow utilizes
gh pr view,gh pr diff, andgit diffto pull external content into the agent's context as shown inSKILL.md. - Boundary markers: There are no instructions or delimiters defined to help the agent distinguish between the skill's instructions and the untrusted content being reviewed.
- Capability inventory: The agent has access to the
Bashtool with permissions to rungit,gh,npm,npx,pytest,go, andcargoas specified in theallowed-toolssection ofSKILL.md. - Sanitization: The skill lacks any instructions for sanitizing or validating external content before it is processed or used in shell commands.
- [REMOTE_CODE_EXECUTION]: In Step 7 ("Verify claims you can check"), the skill instructs the agent to run
gh pr checkoutfollowed bynpm test,npm run typecheck, andnpm run lint. This creates an execution path for arbitrary code defined in the pull request'spackage.jsonor other configuration files, which could be exploited by a malicious contributor to execute code in the agent's environment.
Audit Metadata