ce-resolve-pr-feedback
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes PR comments, review threads, and review bodies which are external, untrusted inputs. This creates a surface where malicious instructions embedded in a PR comment could attempt to influence the agent's code-fixing behavior or command execution.
- Ingestion Points: PR data is fetched in
scripts/get-pr-commentsand used across the orchestrator and fixer subagents. - Boundary Markers: Instructions in
SKILL.mdandreferences/agents/pr-comment-resolver.mdexplicitly warn the agent to treat comment text as untrusted and never execute shell snippets found within them. - Capability Inventory: The skill can execute
ghandgitcommands, modify repository files, and perform git commits and pushes. - Sanitization: The skill relies on independent agent judgment and adherence to safety protocols rather than automated input filtering.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to runghandgitcommands for repository interaction, PR management, and thread resolution. These operations are performed using locally provided scripts that use best practices like heredocs to prevent argument injection from comment content.
Audit Metadata