github-code-review

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a documentation example for a GitHub webhook handler (webhook-handler.js snippet in SKILL.md) that is vulnerable to shell command injection. The code directly interpolates the body of a pull request comment into a shell command executed via execSync without any sanitization or validation. Evidence: execSync(npx ruv-swarm github handle-comment --pr ${event.issue.number} --command "${command}"); where the command variable is derived directly from the untrusted event.comment.body.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface for indirect prompt injection, as it ingests and processes various forms of untrusted data from GitHub pull requests to drive automated agent actions. 1. Ingestion points: Untrusted data enters the agent context via PR_DATA (which includes PR title, body, and labels), PR_DIFF (raw code changes), and PR comments (processed by the webhook handler), all referenced in SKILL.md. 2. Boundary markers: The instructions lack explicit boundary markers or delimiters that would prevent the AI from following malicious instructions embedded within the ingested PR content. 3. Capability inventory: The skill utilizes the GitHub CLI (gh) to perform powerful repository operations including posting reviews, adding labels, and merging pull requests, in addition to orchestrating agents via the ruv-swarm toolset. 4. Sanitization: There is no evidence of sanitization, escaping, or validation logic applied to the external PR content before it is processed or used in shell commands.
  • [DYNAMIC_EXECUTION]: The skill supports the dynamic registration and execution of custom review agents from local JavaScript files at runtime. Evidence: The register-agent command accepts a file path to load executable code: npx ruv-swarm github register-agent --name "custom-reviewer" --file "./custom-review-agent.js".
  • [EXTERNAL_DOWNLOADS]: The skill relies on the npx command to download and execute various components of the ruv-swarm toolset from the author's registry at runtime. Evidence: Multiple commands such as npx ruv-swarm github review-init and npx ruv-swarm github review-security utilize npx for runtime tool execution. These are vendor-owned resources from the author ruvnet.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 06:13 AM
Security Audit — agent-trust-hub — github-code-review