respond-to-issue

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external contributors via GitHub issues.
  • Ingestion points: GitHub issue title, body, and comments are fetched in SKILL.md (Step 1) using the gh issue view command.
  • Boundary markers: The instructions do not provide specific delimiters or ignore-instructions for the agent when processing this external content.
  • Capability inventory: The skill has access to repository metadata and source code via git and gh, and Step 5 describes the capability to create branches and pull requests.
  • Sanitization: There is no explicit sanitization of the fetched issue content before the LLM uses it to research or draft responses.
  • [COMMAND_EXECUTION]: The skill uses shell commands to perform repository operations.
  • Evidence: The workflow utilizes gh issue view, git log, git show, and gh pr list to gather context from the NVIDIA/Megatron-LM repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:19 PM
Security Audit — agent-trust-hub — respond-to-issue