fetch-pr-feedback
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub PR comments. 1. Ingestion points: PR issue and review comments fetched in SKILL.md via gh api calls. 2. Boundary markers: Structured Markdown headers are used in the final document to separate reviewers, providing basic structural separation. 3. Capability inventory: The skill executes gh CLI and jq commands in SKILL.md, and triggers a downstream evaluate and execute loop in the receive-feedback skill. 4. Sanitization: Employs a clean_body filter in SKILL.md that strips HTML comments, bot-specific metadata, and boilerplate footers, while also truncating comments to 4000 characters.
- [COMMAND_EXECUTION]: Employs the GitHub CLI (gh) to view PR details, fetch repository metadata, and query the GitHub API via REST and GraphQL endpoints.
- [DYNAMIC_EXECUTION]: Dynamically generates jq filter scripts in the /tmp directory at runtime to handle complex JSON transformation and filtering of Pull Request comments.
Audit Metadata