Use when reviewing a pull request with runtime or production evidence — for example to review a PR with runtime verification, gather production evidence, or simulate a patch on live samples. Reviews a pull request by diffing against the PR merge base, collecting live samples, and simulating the patch on captured production inputs.
82
85%
Does it follow best practices?
Impact
98%
1.38xAverage score across 2 eval scenarios
Low
Low-risk findings worth noting
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The skill ingests outsider-authored free text in GitHub PR content by fetching the PR diff from a user-supplied `https://github.com/{owner}/{repo}/pull/{number}` (or via GitHub MCP `get_pull_request`) as `pr_base_sha → pr_head_sha`, which the workflow then uses for verification-area derivation and patch simulation.
The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.
The skill declares a runtime MCP tool pointing to https://app.lightrun.com/mcp which is used during execution to call Lightrun APIs (create snapshots, register correlation keys, retrieve captures) and thus is a required external endpoint that can trigger instrumentation/remote actions in production.
d2b954c
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.