get-pr-comments
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes pull request review and discussion comments, which are untrusted external inputs. A malicious contributor could embed instructions within a comment designed to manipulate the agent's summarization or follow-up tasks.
- Ingestion points: PR review and discussion comments (SKILL.md).
- Boundary markers: None described in the workflow.
- Capability inventory: No executable scripts or tool implementations are included in the skill.
- Sanitization: No explicit sanitization of comment content is mentioned.
Audit Metadata