skills/lgtm-hq/ai-skills/sweep-prs/Gen Agent Trust Hub

sweep-prs

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests untrusted data from GitHub PR comments, thread content, and CI logs to drive its assessment and remediation phases.
  • Ingestion points: Data is gathered via gh api and gh pr list in Phase 1, targeting repositories including vendor resources like lgtm-hq/podex and lgtm-hq/py-lintro.
  • Boundary markers: The skill implements a mandatory human confirmation checkpoint (Phase 2) where the user must approve findings before remediation occurs, providing a significant mitigation against automated execution of injected instructions.
  • Capability inventory: The skill has the capability to file new issues, post replies, and resolve threads via Phase 3.
  • Sanitization: There is no evidence of explicit sanitization, validation, or filtering of the external PR content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 05:34 AM
Security Audit — agent-trust-hub — sweep-prs