skills/openhands/extensions/iterate/Gen Agent Trust Hub

iterate

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and acts on feedback from pull request reviews and issue comments (SKILL.md, Steps 3 and 4). \n- Ingestion points: Data is fetched using gh pr view and the GitHub Comments API. \n- Boundary markers: There are no instructions to wrap or delimit these external inputs to prevent the agent from interpreting instructions within the text. \n- Capability inventory: The skill has significant capabilities, including git push and GitHub API operations to modify PR state and request reviews. \n- Sanitization: No filtering or sanitization of the comment body is implemented beyond checking the author association. While filtering for OWNER/MEMBER reduces the risk, the ingestion of untrusted natural language still represents an injection vector. \n- [DYNAMIC_EXECUTION]: The 'Keep .pr/ artifacts fresh' section in SKILL.md requires the agent to 'work out how [an artifact] was generated' by inspecting scripts, documented commands, or file comments, and then to execute those commands to update the artifacts. This logic involves the agent discovering and executing arbitrary commands derived from data within the repository files or history at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — iterate