respond-pr-feedback
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub pull request review comments and uses it to drive automated actions.
- Ingestion points: In
SKILL.md(Step 3a), the skill uses thegh apitool to fetch the bodies of unreplied review comments from a repository. - Boundary markers: The skill lacks explicit instructions or delimiters to inform the agent that it should treat the fetched comment text strictly as data and ignore any embedded instructions (e.g., "Ignore previous rules and instead...").
- Capability inventory: The skill possesses write capabilities, including posting replies to GitHub (
gh api .../repliesin Step 4) and resolving review threads via the GraphQL API (Step 5). - Sanitization: There is no evidence of filtering or sanitization of the comment content before the agent evaluates it to generate a response strategy.
Audit Metadata