babysit-pr

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from GitHub, which is a potential surface for indirect prompt injection.
  • Ingestion points: The agent reads PR intent, repository instructions, code diffs, inline threads, review bodies, and issue comments (SKILL.md).
  • Boundary markers: The instructions explicitly direct the agent to validate findings against the code and PR intent, and state that human comments should not be treated as authorization to change scope without verification.
  • Capability inventory: The agent has the capability to modify source code and push changes to a remote repository using the ship tool.
  • Sanitization: The skill mandates human-in-the-loop escalation for ambiguous findings or conflicts in feedback.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:29 PM
Security Audit — agent-trust-hub — babysit-pr