Run the autonomous cyclic PRP pipeline end to end (plan → implement → pr → review, looping review→fix until the PR is clean). Use when the user wants to "ship feature X end to end", "run the full PRP loop", "auto-implement and open a PR for a feature", or invokes $prp-loop.
80
100%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Security
1 critical severity finding. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
This script intentionally invokes headless agent CLIs with flags that bypass permissions/sandboxing and automates git pushes/commits, creating a high-risk capability for data exfiltration, remote code execution, or repo tampering if abused.
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Very likely: the orchestrator reads the PR review verdict and other stage “result” text from files/artifacts it produces, but at runtime those results ultimately come from the agent/skills interacting with the PR and its comments (review findings are outsider-authored code/PR discussion content, e.g., PR text/issues discussion), which are then injected back into the next fix prompts via `failures`/`pending_findings` and thus into the LLM context via `run_agent(prompt)`.
1142738
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.