github-repo-monitor
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes untrusted data from GitHub issue and pull request comments, which are then interpolated into the prompt of a newly created OpenHands conversation, establishing an indirect prompt injection surface.\n
- Ingestion points:
scripts/main.pyfetches external comment data via the GitHub API using the_poll_issue_commentsand_poll_pr_review_commentsfunctions.\n - Boundary markers: In
scripts/main.py, the_build_initial_promptfunction utilizes triple-dash (---) delimiters to separate untrusted content from instructions, but it lacks specific directives for the agent to ignore or neutralize embedded commands within that content.\n - Capability inventory: The spawned AI agent is configured with
terminalandfile_editortools, and the automation has access to aGITHUB_PERSONAL_ACCESS_TOKENfor repository interactions.\n - Sanitization: The skill does not perform explicit sanitization, filtering, or validation of the fetched comment body before it is passed to the AI agent.
Audit Metadata