load-pr-comments
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several shell commands using the GitHub CLI (
gh) and standard utilities likegrep,printf, andmkdirto perform its tasks. - These commands are used to authenticate, fetch pull request metadata, query the GraphQL API, and manage local task files.
- The use of these tools is aligned with the skill's stated function of pull request management and task aggregation.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from external GitHub PR comments and prepares it as instructions for other AI agents.
- Ingestion points: Pull request comments are retrieved from external repositories via the GitHub GraphQL API (
gh api graphql) or themcp__MCP_DOCKER__pull_request_readtool. - Boundary markers: While the skill organizes data into a Markdown template, it lacks explicit delimiters or instructions for downstream agents to ignore embedded commands within the fetched comments.
- Capability inventory: The skill has file system access for directory creation and file writing, as well as shell execution capabilities using the GitHub CLI.
- Sanitization: There is a lack of sanitization; the instructions explicitly require the agent to preserve comment substance verbatim, which potentially includes malicious payload instructions hidden in pull request feedback designed to influence subsequent agent actions.
Audit Metadata