address-github-comments
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its processing of external, untrusted GitHub comments.\n- Ingestion points: Data enters the agent context from GitHub comments fetched via
gh pr view --commentsin SKILL.md.\n- Boundary markers: The skill lacks explicit markers or instructions to distinguish untrusted comment content from system instructions.\n- Capability inventory: The agent has capabilities to modify local source code and interact with the GitHub API via theghtool.\n- Sanitization: No validation or sanitization is performed on the incoming comment text before it is used to plan and apply code changes.\n- Mitigation: Implement strict boundary markers around fetched comments and explicitly instruct the agent to ignore any commands or instructions found within those comments. The existing step to wait for user confirmation is an effective human-in-the-loop mitigation.
Audit Metadata