review-dispatch

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from git diffs, commit logs, and pull request metadata which may contain malicious instructions designed to influence the agent's behavior.\n
  • Ingestion points: The skill retrieves untrusted data using git diff, gh pr diff, and git log commands during the target resolution phase in SKILL.md.\n
  • Boundary markers: The instructions explicitly state that diffs and metadata are untrusted input and caution the agent against obeying instructions embedded within reviewed code.\n
  • Capability inventory: The agent can read repository data and create GitHub issues via the gh CLI tool.\n
  • Sanitization: The skill uses temporary files for issue bodies to prevent shell injection and requires a human-in-the-loop confirmation step before filing any issue.\n- [COMMAND_EXECUTION]: The skill relies on shell commands to interact with the local environment and the GitHub API.\n
  • Evidence: SKILL.md contains several bash blocks for resolving the default branch, fetching commits, and executing issue creation via gh issue create.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — review-dispatch