load-pr-comments

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several shell commands using the GitHub CLI (gh) and standard utilities like grep, printf, and mkdir to perform its tasks.
  • These commands are used to authenticate, fetch pull request metadata, query the GraphQL API, and manage local task files.
  • The use of these tools is aligned with the skill's stated function of pull request management and task aggregation.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from external GitHub PR comments and prepares it as instructions for other AI agents.
  • Ingestion points: Pull request comments are retrieved from external repositories via the GitHub GraphQL API (gh api graphql) or the mcp__MCP_DOCKER__pull_request_read tool.
  • Boundary markers: While the skill organizes data into a Markdown template, it lacks explicit delimiters or instructions for downstream agents to ignore embedded commands within the fetched comments.
  • Capability inventory: The skill has file system access for directory creation and file writing, as well as shell execution capabilities using the GitHub CLI.
  • Sanitization: There is a lack of sanitization; the instructions explicitly require the agent to preserve comment substance verbatim, which potentially includes malicious payload instructions hidden in pull request feedback designed to influence subsequent agent actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:55 AM
Security Audit — agent-trust-hub — load-pr-comments