pre-pr-review
Warn
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs several shell operations to analyze the repository state, including
git status,git add -N ., andgit diff. It also uses shell logic withsedto identify the default branch name. These commands interact directly with the local environment. - [REMOTE_CODE_EXECUTION]: In Step 2, the skill directs the agent to locate and execute build, lint, and test scripts specified in the project being reviewed (e.g., in
package.json,README.md, orCLAUDE.md). This instruction allows the execution of arbitrary shell commands found in the repository's configuration, which poses a significant risk if the repository is malicious. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests and processes untrusted code diffs and documentation. Ingestion points: Code diffs and project metadata files. Boundary markers: None provided; the agent processes the diff content directly within its context. Capability inventory: Execution of shell commands and filesystem access. Sanitization: No validation or sanitization is performed on the ingested diff content, which could allow malicious instructions embedded in code comments to manipulate the agent's review logic or verdict.
Audit Metadata