fix-pr-comments
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through pull request review comments, although it incorporates multiple layers of protection.
- Ingestion points:
pr-threads.shretrieves comment content from the GitHub API usinggh api graphql. - Boundary markers: Present in
SKILL.md; the agent is explicitly instructed to treat comments as non-authoritative "claims" and is warned that bot comments may quote untrusted text from the PR author. - Capability inventory: The skill allows the agent to modify the local codebase to fix issues and execute
gh apicalls to post replies and resolve threads on GitHub. - Sanitization: Present in
pr-threads.sh; comment data is filtered against a hardcoded list of verified bot database IDs to exclude input from humans or untrusted automated actors. - [COMMAND_EXECUTION]: The skill executes the
ghCLI and thepr-threads.shscript to perform PR operations. These commands are targeted at the intended functionality of the skill.
Audit Metadata