skills/wuchendi/skills/pre-pr-review/Gen Agent Trust Hub

pre-pr-review

Warn

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs several shell operations to analyze the repository state, including git status, git add -N ., and git diff. It also uses shell logic with sed to identify the default branch name. These commands interact directly with the local environment.
  • [REMOTE_CODE_EXECUTION]: In Step 2, the skill directs the agent to locate and execute build, lint, and test scripts specified in the project being reviewed (e.g., in package.json, README.md, or CLAUDE.md). This instruction allows the execution of arbitrary shell commands found in the repository's configuration, which poses a significant risk if the repository is malicious.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests and processes untrusted code diffs and documentation. Ingestion points: Code diffs and project metadata files. Boundary markers: None provided; the agent processes the diff content directly within its context. Capability inventory: Execution of shell commands and filesystem access. Sanitization: No validation or sanitization is performed on the ingested diff content, which could allow malicious instructions embedded in code comments to manipulate the agent's review logic or verdict.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 14, 2026, 12:22 AM