review-pr

Fail

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: HIGHINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands found in external, user-editable fields. Evidence: The instruction 'run the ticket's ## Verify block yourself' in 'SKILL.md' directs the agent to execute shell commands provided in a GitHub issue.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to instructions embedded in data it processes from GitHub and git history. Ingestion points: 'gh issue view', 'gh pr view', and 'git notes --ref=sdd-verify show HEAD' in 'SKILL.md' provide the untrusted input. Boundary markers: None. The agent is not instructed to sanitize or validate the commands within these blocks before execution. Capability inventory: The agent has access to the shell, the repository files, and the 'gh' command-line tool. Sanitization: The skill lacks any mechanism to ensure that the commands extracted from external sources are safe or restricted.
  • [REMOTE_CODE_EXECUTION]: The workflow implements a remote code execution pattern where code is fetched from a remote issue tracker and executed locally. Evidence: The sequence of gathering issue content and git notes and then executing a specific block of that content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 28, 2026, 05:42 PM
Security Audit — agent-trust-hub — review-pr