ce-resolve-pr-feedback

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes PR comments, review threads, and review bodies which are external, untrusted inputs. This creates a surface where malicious instructions embedded in a PR comment could attempt to influence the agent's code-fixing behavior or command execution.
  • Ingestion Points: PR data is fetched in scripts/get-pr-comments and used across the orchestrator and fixer subagents.
  • Boundary Markers: Instructions in SKILL.md and references/agents/pr-comment-resolver.md explicitly warn the agent to treat comment text as untrusted and never execute shell snippets found within them.
  • Capability Inventory: The skill can execute gh and git commands, modify repository files, and perform git commits and pushes.
  • Sanitization: The skill relies on independent agent judgment and adherence to safety protocols rather than automated input filtering.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run gh and git commands for repository interaction, PR management, and thread resolution. These operations are performed using locally provided scripts that use best practices like heredocs to prevent argument injection from comment content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:31 PM
Security Audit — agent-trust-hub — ce-resolve-pr-feedback