address-pr-comments

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from GitHub pull request comments which could contain malicious instructions.
  • Ingestion points: In SKILL.md (Step 2) and references/gh-api-reference.md, the skill fetches review comments using the GitHub API (gh api repos/{owner}/{repo}/pulls/{pr_number}/comments).
  • Boundary markers: The instructions do not specify any boundary markers (such as XML tags or delimiters) to isolate the untrusted comment bodies from the agent's core instructions, nor do they include warnings to ignore embedded commands.
  • Capability inventory: The skill has powerful capabilities, including reading local source files, making code modifications (Step 5), and performing network write operations via the GitHub API (Step 8).
  • Sanitization: There is no mention of sanitizing, escaping, or validating the comment text before it is evaluated by the agent for code changes or reply generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — address-pr-comments