review-pr

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Executes a bundled bash script prepare-pr-branch.sh and various system CLI tools including git, gh (GitHub CLI), rg (ripgrep), and defaults.
  • [EXTERNAL_DOWNLOADS]: Fetches repository content and PR/Issue metadata from GitHub remotes and contributor forks using well-known services.
  • [PROMPT_INJECTION]: Vulnerable to indirect prompt injection from external GitHub content. 1. Ingestion points: Fetches untrusted data via gh pr view and gh issue view (e.g., PR bodies, comments, and linked issues). 2. Boundary markers: None. The skill does not instruct the agent to distinguish between its instructions and the external content. 3. Capability inventory: The agent has access to git, gh, and bash for local operations. 4. Sanitization: None. The external text is processed directly without filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 04:37 PM
Security Audit — agent-trust-hub — review-pr