address-github-comments

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its processing of external, untrusted GitHub comments.\n- Ingestion points: Data enters the agent context from GitHub comments fetched via gh pr view --comments in SKILL.md.\n- Boundary markers: The skill lacks explicit markers or instructions to distinguish untrusted comment content from system instructions.\n- Capability inventory: The agent has capabilities to modify local source code and interact with the GitHub API via the gh tool.\n- Sanitization: No validation or sanitization is performed on the incoming comment text before it is used to plan and apply code changes.\n- Mitigation: Implement strict boundary markers around fetched comments and explicitly instruct the agent to ignore any commands or instructions found within those comments. The existing step to wait for user confirmation is an effective human-in-the-loop mitigation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — address-github-comments