forge-address-pr-feedback

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests review comments from pull request threads, which are provided by external users. This data is analyzed to determine code changes and formulated replies, creating an attack surface where malicious instructions in a comment could influence the agent.
  • Evidence: Step 1 uses gh api graphql to retrieve comments from reviewThreads, and Step 2 directs the agent to analyze these comments.
  • Vulnerability tier: Tier 1 (Simple ingestion of external text for instruction following).
  • Capability tier: Tier 2 (Ability to write to the file system, commit changes, and interact with repository APIs).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:27 PM
Security Audit — agent-trust-hub — forge-address-pr-feedback