fetch-pr-feedback

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub PR comments. 1. Ingestion points: PR issue and review comments fetched in SKILL.md via gh api calls. 2. Boundary markers: Structured Markdown headers are used in the final document to separate reviewers, providing basic structural separation. 3. Capability inventory: The skill executes gh CLI and jq commands in SKILL.md, and triggers a downstream evaluate and execute loop in the receive-feedback skill. 4. Sanitization: Employs a clean_body filter in SKILL.md that strips HTML comments, bot-specific metadata, and boilerplate footers, while also truncating comments to 4000 characters.
  • [COMMAND_EXECUTION]: Employs the GitHub CLI (gh) to view PR details, fetch repository metadata, and query the GitHub API via REST and GraphQL endpoints.
  • [DYNAMIC_EXECUTION]: Dynamically generates jq filter scripts in the /tmp directory at runtime to handle complex JSON transformation and filtering of Pull Request comments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:17 AM
Security Audit — agent-trust-hub — fetch-pr-feedback