respond-to-issue
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external contributors via GitHub issues.
- Ingestion points: GitHub issue title, body, and comments are fetched in SKILL.md (Step 1) using the
gh issue viewcommand. - Boundary markers: The instructions do not provide specific delimiters or ignore-instructions for the agent when processing this external content.
- Capability inventory: The skill has access to repository metadata and source code via
gitandgh, and Step 5 describes the capability to create branches and pull requests. - Sanitization: There is no explicit sanitization of the fetched issue content before the LLM uses it to research or draft responses.
- [COMMAND_EXECUTION]: The skill uses shell commands to perform repository operations.
- Evidence: The workflow utilizes
gh issue view,git log,git show, andgh pr listto gather context from theNVIDIA/Megatron-LMrepository.
Audit Metadata