gh-address-comments
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill and its associated script (
scripts/fetch_comments.py) rely on thegh(GitHub CLI) tool to perform repository operations, including authentication checks (gh auth status), viewing PR metadata (gh pr view), and executing GraphQL queries (gh api graphql). These are standard operations for the skill's stated purpose. - [EXTERNAL_DOWNLOADS]: The Python script fetches pull request data, including conversation comments and review threads, from the GitHub API. This data originates from external contributors and is processed by the agent to fulfill the skill's goals.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it processes untrusted input from external sources.
- Ingestion points: The
fetch_allfunction inscripts/fetch_comments.pyretrieves comments, reviews, and review threads via the GitHub GraphQL API. - Boundary markers: No explicit boundary markers or instructions to treat external comment text as untrusted are defined in
SKILL.mdor the Python script. - Capability inventory: The skill instructions explicitly direct the agent to "Apply fixes for selected items" and "Implement the smallest safe change," which grants the agent capability to modify the local filesystem based on instructions contained within the ingested comments.
- Sanitization: No sanitization, validation, or filtering of the fetched comment content is performed before it is presented to the agent for processing.
- [SAFE]: The bundled Python script uses standard library modules and follows security best practices for executing subprocesses, such as passing arguments as a list and using
stdinfor GraphQL queries to avoid shell injection vulnerabilities.
Audit Metadata