bug-review
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted code changes from pull requests, which could contain malicious text designed to manipulate the review agents or influence the generation of automated fixes.
- Ingestion points: PR diff content is fetched via
scripts/fetch-pr.shand processed by the review agents. - Boundary markers: The prompts in
references/review-passes.mdspecify the focus areas, but the skill does not use explicit delimiters to separate untrusted code from instructions. - Capability inventory: The skill can post comments to GitHub repositories using the
ghCLI and suggest/apply code changes using theEdittool. - Sanitization: This risk is significantly mitigated by a 5-pass majority voting system (3/5 threshold), an independent validator agent (Opus) that has not seen the previous findings, and a mandatory user selection step before any findings are posted or fixes applied.
- [COMMAND_EXECUTION]: The skill relies on local CLI tools for repository analysis and GitHub interaction.
- Evidence: Extensive use of
gh,git,jq,bc,grep, andsedacross the script suite for fetching PR data, extracting context, and posting reviews. - Mitigation: Input identifiers like PR numbers are resolved and validated via the
ghCLI before being used in shell operations. - [DYNAMIC_EXECUTION]: The skill implements a self-optimizing configuration loop that adjusts its own behavior based on historical performance.
- Evidence:
scripts/update-weights.shmodifies the skill'sconfig.jsonto deprioritize or suppress bug categories that developers consistently ignore, representing a controlled self-modification feature. - [SAFE]: The skill implements proactive safety guardrails through platform hooks.
- Evidence:
hooks/hooks.jsondefines Bash hooks that block destructive operations likegit push --forceorgit reset --hard, and Edit hooks that warn if a proposed autofix exceeds a safe scope (1 file or 20 lines).
Audit Metadata