review-pr
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from pull request diffs, descriptions, and linked issues, which creates a surface for indirect prompt injection attacks where malicious instructions embedded in the code or PR text could attempt to manipulate the agent's review logic.
- Ingestion points: The skill reads from
pr_diff.txt,pr_description.txt, and data fetched from GitHub viascripts/resolve_spec_context.py. - Boundary markers: While the skill provides strict instructions on interpreting diff annotations, it lacks explicit delimiters or encapsulation for the broader untrusted text inputs.
- Capability inventory: The agent has the ability to write files (
review.json) and execute internal validation scripts via the shell. - Sanitization: There is no automated sanitization layer identified for the external data ingested during the review process.
- [EXTERNAL_DOWNLOADS]: The skill retrieves pull request data and specification documents from a well-known service to provide context for the review.
- The script
scripts/resolve_spec_context.pyconnects toapi.github.comusing standard GitHub API protocols. - It fetches JSON and Markdown content related to pull requests and issues using an authentication token provided through environment variables.
- [COMMAND_EXECUTION]: The skill uses a bundled Python script to validate the integrity of the review artifact before finalization.
- The agent is instructed to execute
scripts/validate_review_json.pylocally to check thereview.jsonfile against the provided diff. - This execution is limited to specific files included within the skill package.
Audit Metadata