review-pr

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from pull request diffs, descriptions, and linked issues, which creates a surface for indirect prompt injection attacks where malicious instructions embedded in the code or PR text could attempt to manipulate the agent's review logic.
  • Ingestion points: The skill reads from pr_diff.txt, pr_description.txt, and data fetched from GitHub via scripts/resolve_spec_context.py.
  • Boundary markers: While the skill provides strict instructions on interpreting diff annotations, it lacks explicit delimiters or encapsulation for the broader untrusted text inputs.
  • Capability inventory: The agent has the ability to write files (review.json) and execute internal validation scripts via the shell.
  • Sanitization: There is no automated sanitization layer identified for the external data ingested during the review process.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves pull request data and specification documents from a well-known service to provide context for the review.
  • The script scripts/resolve_spec_context.py connects to api.github.com using standard GitHub API protocols.
  • It fetches JSON and Markdown content related to pull requests and issues using an authentication token provided through environment variables.
  • [COMMAND_EXECUTION]: The skill uses a bundled Python script to validate the integrity of the review artifact before finalization.
  • The agent is instructed to execute scripts/validate_review_json.py locally to check the review.json file against the provided diff.
  • This execution is limited to specific files included within the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:32 PM
Security Audit — agent-trust-hub — review-pr