pr-review
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by reading GitHub Pull Request diffs and descriptions. This content could contain malicious instructions intended to manipulate the agent's review output or summary.
- Ingestion points: Pull Request content retrieved via
gh pr diffandgh pr viewinSKILL.md. - Boundary markers: None identified; the agent is instructed to read the full content without explicit delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill has the capability to write back to the external source using
gh pr review. - Sanitization: No sanitization or validation of the PR content is specified before processing.
- [COMMAND_EXECUTION]: The skill uses the GitHub CLI (
gh) to perform its primary functions, including viewing diffs and submitting reviews. This is consistent with the stated purpose of the skill.
Audit Metadata