pr-49-review
Pass
Audited by Gen Agent Trust Hub on Feb 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes untrusted data from a GitHub Pull Request (description and code diff) which could contain embedded instructions targeting the agent's behavior.
- Ingestion points: Output retrieved via
gh pr viewandgh pr diffcommands as specified inSKILL.md. - Boundary markers: The instructions do not employ delimiters (e.g., XML tags) or specific directives to ignore instructions found within the PR content.
- Capability inventory: Usage of the
gh(GitHub CLI) tool for repository interaction. - Sanitization: No validation or filtering is performed on the PR text before it is presented to the agent context.
Audit Metadata