gh-address-comments
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute repository-specific tests and checks (Step 4). This involves running arbitrary shell commands within the user's environment to verify code changes, which is a standard but sensitive capability.
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it processes untrusted content from GitHub pull request review threads.
- Ingestion points: GitHub review comments retrieved via
gh api graphqlor the referencedscripts/fetch_comments.pyscript. - Boundary markers: The instructions do not define explicit delimiters for untrusted comment data, though it advises the agent to seek clarification for ambiguous input.
- Capability inventory: The skill possesses the ability to modify files (implementing fixes), execute shell commands (running tests), and perform network operations via the GitHub API (replies and thread resolution).
- Sanitization: No explicit sanitization or filtering of comment content is described, relying instead on the agent's interpretation and the user's oversight of the final summary.
- [EXTERNAL_DOWNLOADS]: The skill mentions a dependency on
scripts/fetch_comments.py. While presented as a plugin-provided component installed alongside the skill, this represents an external script dependency that must be verified as part of the local environment.
Audit Metadata