prs-reviewed
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions in
SKILL.mdspecify direct interpolation of user-supplied arguments (<username>,<num>) into shell commands executed via thegh apitool. This pattern is vulnerable to command injection if the agent does not strictly validate the input for shell metacharacters such as backticks, semicolons, or subshells. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub pull requests, such as titles and author names, which are then rendered into a markdown table for the user.
- Ingestion points: External GitHub Search API and Pull Request Reviews API responses processed in
SKILL.md(Step 2). - Boundary markers: None present; the skill displays external content directly without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill possesses the ability to execute shell commands via the
ghCLI as documented inSKILL.md. - Sanitization: No sanitization, escaping, or validation of the fetched PR titles or author fields is performed before interpolation into the final output.
Audit Metadata