github-repo-monitor

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes untrusted data from GitHub issue and pull request comments, which are then interpolated into the prompt of a newly created OpenHands conversation, establishing an indirect prompt injection surface.\n
  • Ingestion points: scripts/main.py fetches external comment data via the GitHub API using the _poll_issue_comments and _poll_pr_review_comments functions.\n
  • Boundary markers: In scripts/main.py, the _build_initial_prompt function utilizes triple-dash (---) delimiters to separate untrusted content from instructions, but it lacks specific directives for the agent to ignore or neutralize embedded commands within that content.\n
  • Capability inventory: The spawned AI agent is configured with terminal and file_editor tools, and the automation has access to a GITHUB_PERSONAL_ACCESS_TOKEN for repository interactions.\n
  • Sanitization: The skill does not perform explicit sanitization, filtering, or validation of the fetched comment body before it is passed to the AI agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — github-repo-monitor