ork-review-pr
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data (pull request diffs and repository context) which can contain malicious instructions designed to influence the agent's behavior during review.
- Ingestion points: Repository diffs and changed behavior context specified in
SKILL.md. - Boundary markers: Absent; the instructions do not define specific delimiters or warnings to ignore instructions embedded within the diff data.
- Capability inventory: Includes file system reading and repository exploration as mentioned in the instructions to trace behavior and verify documentation.
- Sanitization: No sanitization, validation, or escaping of the ingested diff content is specified.
Audit Metadata