get-pr-comments

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted content from pull request review and discussion comments, which is a potential surface for indirect prompt injection.
  • Ingestion points: Pull request comments resolved from the active branch (SKILL.md).
  • Boundary markers: Absent. The workflow does not specify delimiters to separate fetched data from the prompt logic.
  • Capability inventory: No tool calls, scripts, or subprocess executions are defined within the skill itself.
  • Sanitization: Absent.
  • [NO_CODE]: This skill contains only markdown instructions and no executable scripts or code files, which significantly reduces the attack surface for malicious logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 08:52 AM
Security Audit — agent-trust-hub — get-pr-comments