get-pr-comments

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes pull request review and discussion comments, which are untrusted external inputs. A malicious contributor could embed instructions within a comment designed to manipulate the agent's summarization or follow-up tasks.
  • Ingestion points: PR review and discussion comments (SKILL.md).
  • Boundary markers: None described in the workflow.
  • Capability inventory: No executable scripts or tool implementations are included in the skill.
  • Sanitization: No explicit sanitization of comment content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 09:17 AM
Security Audit — agent-trust-hub — get-pr-comments