gh-address-comments

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute repository-specific tests and checks (Step 4). This involves running arbitrary shell commands within the user's environment to verify code changes, which is a standard but sensitive capability.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it processes untrusted content from GitHub pull request review threads.
  • Ingestion points: GitHub review comments retrieved via gh api graphql or the referenced scripts/fetch_comments.py script.
  • Boundary markers: The instructions do not define explicit delimiters for untrusted comment data, though it advises the agent to seek clarification for ambiguous input.
  • Capability inventory: The skill possesses the ability to modify files (implementing fixes), execute shell commands (running tests), and perform network operations via the GitHub API (replies and thread resolution).
  • Sanitization: No explicit sanitization or filtering of comment content is described, relying instead on the agent's interpretation and the user's oversight of the final summary.
  • [EXTERNAL_DOWNLOADS]: The skill mentions a dependency on scripts/fetch_comments.py. While presented as a plugin-provided component installed alongside the skill, this represents an external script dependency that must be verified as part of the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 12:10 PM
Security Audit — agent-trust-hub — gh-address-comments