Use when reviewing a pull request with runtime or production evidence — for example to review a PR with runtime verification, gather production evidence, or simulate a patch on live samples. Reviews a pull request by diffing against the PR merge base, collecting live samples, and simulating the patch on captured production inputs.
90
96%
Does it follow best practices?
Impact
98%
1.38xAverage score across 2 eval scenarios
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The runtime workflow uses GitHub compare/PR diff data to derive verification areas and then queries Lightrun runtime hits/snapshots, so outsider-authored free text from the PR (e.g., changed files/diff content) is read at runtime and can carry indirect prompt-injection payloads.
ba8e25a
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.