gh-discuss
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub Discussion threads. Ingestion points: The discussion body and author login are fetched via
gh api graphqlinSKILL.md. Boundary markers: No explicit delimiters are present to separate the external discussion text from instructions. Capability inventory: The skill allows reading repository files and posting a discussion comment usinggh api graphql. Sanitization: There is no validation or filtering of the discussion content before it is used to form a reply.
Audit Metadata