review-pr
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Executes a bundled bash script
prepare-pr-branch.shand various system CLI tools includinggit,gh(GitHub CLI),rg(ripgrep), anddefaults. - [EXTERNAL_DOWNLOADS]: Fetches repository content and PR/Issue metadata from GitHub remotes and contributor forks using well-known services.
- [PROMPT_INJECTION]: Vulnerable to indirect prompt injection from external GitHub content. 1. Ingestion points: Fetches untrusted data via
gh pr viewandgh issue view(e.g., PR bodies, comments, and linked issues). 2. Boundary markers: None. The skill does not instruct the agent to distinguish between its instructions and the external content. 3. Capability inventory: The agent has access togit,gh, andbashfor local operations. 4. Sanitization: None. The external text is processed directly without filtering.
Audit Metadata