sweep-prs
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests untrusted data from GitHub PR comments, thread content, and CI logs to drive its assessment and remediation phases.
- Ingestion points: Data is gathered via
gh apiandgh pr listin Phase 1, targeting repositories including vendor resources likelgtm-hq/podexandlgtm-hq/py-lintro. - Boundary markers: The skill implements a mandatory human confirmation checkpoint (Phase 2) where the user must approve findings before remediation occurs, providing a significant mitigation against automated execution of injected instructions.
- Capability inventory: The skill has the capability to file new issues, post replies, and resolve threads via Phase 3.
- Sanitization: There is no evidence of explicit sanitization, validation, or filtering of the external PR content before it is processed by the agent.
Audit Metadata