address-github-comments
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources (GitHub PR/issue comments) which are processed to generate code fixes. This represents an indirect prompt injection surface where a malicious comment could attempt to influence the agent's code generation or command execution.
- Ingestion points: GitHub PR comments fetched via
gh pr view --commentsinSKILL.md. - Boundary markers: None specified in the instructions.
- Capability inventory: The skill is designed to apply code changes (Step 3) and execute network commands via
gh(Step 4). - Sanitization: No explicit sanitization or instruction-ignoring delimiters are defined for the fetched comment text.
- [COMMAND_EXECUTION]: The skill relies on executing the
ghCLI to interact with GitHub, including authentication checks, viewing PR data, and posting comments. These are standard operations for the stated purpose but involve shell command execution.
Audit Metadata