address-github-comments

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub pull request comments, which presents an attack surface for indirect prompt injection.
  • Ingestion points: The skill fetches external review and issue comments via gh pr view --comments (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish fetched comment text from operational instructions.
  • Capability inventory: The skill performs command execution via the GitHub CLI (gh) and involves file system modifications to apply fixes (SKILL.md).
  • Sanitization: No sanitization, filtering, or validation of the external comment content is specified.
  • [COMMAND_EXECUTION]: The skill uses the GitHub CLI to perform repository operations.
  • Evidence: Executes gh auth status, gh pr view --comments, and gh pr comment to interact with GitHub services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — address-github-comments