pre-pr-review

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an orchestrator that ingests untrusted external data, which could be manipulated to influence the agent's behavior during the review process.\n
  • Ingestion points: The workflow reads external files including shared/references/review-evidence.md, task reports, integration reports, and repository diffs as specified in SKILL.md.\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded instructions are defined for the ingested data.\n
  • Capability inventory: The skill is configured to invoke child skills such as full-review, verify-changes, browser-smoke, coding-review-simplify, review-gate, and diagnose, and it writes artifacts to a temporary directory as defined in SKILL.md.\n
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation steps for the data processed from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:42 PM
Security Audit — agent-trust-hub — pre-pr-review