reviewing-prs — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited reviewing-prs (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
gh pr view <number> --json title,body,baseRefName,headRefName,files,additions,deletions
gh pr diff <number>
gh pr view <number> --json reviews,commentsPass the PR number, title, diff, and file list to each sub-agent.
Launch all three sub-agents in parallel using the Agent tool. Each agent receives:
Each sub-agent must return a structured review following the format in their instructions. Do not ask them to post comments — only the main agent posts.
Read all three reviews. Deduplicate overlapping findings. Assign a final severity to each issue:
gh pr comment <number> --body "$(cat <<'EOF'
<synthesized review — see COMMENT-TEMPLATE.md>
EOF
)"Always:
Ask first:
Never:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.