Back to skill

Security audit

PR Review Factory

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent PR automation, but it can make persistent GitHub repository changes and merge-related decisions without clear confirmation gates.

Review this carefully before installing. Use it only on repositories where automated issue creation, workflow changes, and merge gating are acceptable, and prefer least-privilege GitHub tokens plus explicit approval before any write or merge-related action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that merge is triggered after all blocking issues are closed, but it does not present this auto-merge behavior as a prominent risk or require explicit opt-in. Automatic merging is especially sensitive because it can directly change the default branch state; if users misunderstand the behavior, an agent could merge code based on incomplete review or misconfigured issue state.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises end-to-end automation but does not prominently warn that it can modify repository state by creating issues, generating CI workflows, assigning work, and auto-merging pull requests. Users may interpret it as analysis-only, leading to informed-consent failures and unintended changes to code, CI, and governance controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README describes actions that create Issues, assign users, deploy GitHub Actions workflows, and enforce merge-gating, but it does not clearly foreground that these are repository-modifying operations requiring explicit user confirmation. In an agent setting, ambiguous documentation increases the chance that a user invokes the skill expecting analysis only while the skill performs side effects that alter project state and workflow behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase at this location is broad enough to match ordinary review requests, which can cause the skill to activate in contexts where the user did not intend a repository-affecting workflow. Because this skill can create issues, generate workflows, and eventually merge PRs, accidental invocation could lead to unauthorized or surprising state changes in GitHub repositories.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These trigger phrases are ambiguous and do not clearly limit scope, making it easy for normal conversational requests to invoke automation with write effects. In this skill's context, ambiguous activation is more dangerous because the downstream actions include persistent repository modifications and automated quality-gate changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Mentioning use of a GitHub token without a security warning omits important guidance about token scope, storage, and exposure risks. In a skill that can perform administrative repository actions, over-privileged or mishandled tokens could enable broad unauthorized changes if leaked or misused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description and user-facing labels/keywords are presented in Chinese, with no indication that the user can choose language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manual trigger keywords are very broad generic review terms such as 'Code Review', '代码审查', and 'PR合并', which can cause the workflow to activate in response to common user requests rather than an explicit request for this specific automation. Because the workflow creates issues, deploys GitHub Actions, and influences merge readiness, accidental invocation could lead to unintended repository modifications and automation side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire skill description, examples, and user interaction text are presented in Chinese, with no indication that other languages are supported or that Chinese is a deliberate, justified locale restriction. This can be a natural-language policy issue when a skill effectively imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill metadata and usage examples are presented entirely in Chinese, including trigger phrases, with no indication that other languages are supported or that the user may choose their preferred language. This creates a locale/language constraint that is not documented as optional or justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.