skills/tisfeng/easydict/review-pr/Gen Agent Trust Hub

review-pr

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub Pull Requests, including descriptions, comments, and code diffs.\n
  • Ingestion points: Data enters the context via gh pr view (body, comments, files) and git diff as specified in SKILL.md.\n
  • Boundary markers: Instructions do not define specific delimiters or "ignore" blocks for isolating PR data from instructions.\n
  • Capability inventory: The skill uses git and gh CLI tools to modify local repository state (checkout, merge, add, commit) as seen in scripts/prepare-pr-branch.sh.\n
  • Sanitization: The agent is instructed to logically evaluate PR feedback rather than executing it, serving as a functional filter.\n- [COMMAND_EXECUTION]: The skill and its test suite execute system commands via git and gh. The Python tests in tests/test_prepare_pr_branch.py use subprocess.run with argument lists to safely execute these commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 01:49 PM
Security Audit — agent-trust-hub — review-pr