address-github-comments
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub pull request comments, which presents an attack surface for indirect prompt injection.
- Ingestion points: The skill fetches external review and issue comments via
gh pr view --comments(SKILL.md). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish fetched comment text from operational instructions.
- Capability inventory: The skill performs command execution via the GitHub CLI (
gh) and involves file system modifications to apply fixes (SKILL.md). - Sanitization: No sanitization, filtering, or validation of the external comment content is specified.
- [COMMAND_EXECUTION]: The skill uses the GitHub CLI to perform repository operations.
- Evidence: Executes
gh auth status,gh pr view --comments, andgh pr commentto interact with GitHub services.
Audit Metadata