code-review
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted pull request data including code diffs, titles, and descriptions. This creates a surface for indirect prompt injection where malicious instructions embedded in a PR could influence the agent to bypass review standards or perform unintended actions.\n
- Ingestion points: PR metadata and code changes retrieved via
ghcommands and file system access as described inSKILL.mdandreferences/github-pr-review-actions.md.\n - Boundary markers: None identified in the provided instructions to separate untrusted content from the agent's instructions.\n
- Capability inventory: File read/write access and
ghCLI execution for interaction with the GitHub API.\n - Sanitization: No explicit sanitization or escaping of the untrusted PR content is defined before processing.\n- [COMMAND_EXECUTION]: The skill instructions in
references/github-pr-review-actions.mdandreferences/ci-optimized-workflow.mdrely on thegh(GitHub CLI) tool to retrieve PR data and post review results. These commands are executed in the shell to interact with the official GitHub API.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing additional skills fromvercel-labs(a well-known service) and the authorxtone. These references are documented as part of the intended workflow for extending code review capabilities.
Audit Metadata