skills/lsegal/glorp/gh-discuss/Gen Agent Trust Hub

gh-discuss

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub Discussion threads. Ingestion points: The discussion body and author login are fetched via gh api graphql in SKILL.md. Boundary markers: No explicit delimiters are present to separate the external discussion text from instructions. Capability inventory: The skill allows reading repository files and posting a discussion comment using gh api graphql. Sanitization: There is no validation or filtering of the discussion content before it is used to form a reply.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 09:38 PM
Security Audit — agent-trust-hub — gh-discuss