get-pr-comments
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted content from pull request review and discussion comments, which is a potential surface for indirect prompt injection.
- Ingestion points: Pull request comments resolved from the active branch (SKILL.md).
- Boundary markers: Absent. The workflow does not specify delimiters to separate fetched data from the prompt logic.
- Capability inventory: No tool calls, scripts, or subprocess executions are defined within the skill itself.
- Sanitization: Absent.
- [NO_CODE]: This skill contains only markdown instructions and no executable scripts or code files, which significantly reduces the attack surface for malicious logic.
Audit Metadata