review-pr
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub Pull Requests, including descriptions, comments, and code diffs.\n
- Ingestion points: Data enters the context via
gh pr view(body, comments, files) andgit diffas specified inSKILL.md.\n - Boundary markers: Instructions do not define specific delimiters or "ignore" blocks for isolating PR data from instructions.\n
- Capability inventory: The skill uses
gitandghCLI tools to modify local repository state (checkout, merge, add, commit) as seen inscripts/prepare-pr-branch.sh.\n - Sanitization: The agent is instructed to logically evaluate PR feedback rather than executing it, serving as a functional filter.\n- [COMMAND_EXECUTION]: The skill and its test suite execute system commands via
gitandgh. The Python tests intests/test_prepare_pr_branch.pyusesubprocess.runwith argument lists to safely execute these commands.
Audit Metadata