resolve-pr-parallel

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub PR comments and reviews, using the content as direct instructions for parallel sub-agents.
  • Ingestion points: The skill fetches external content using gh pr view and gh api repos/{owner}/{repo}/pulls/PR_NUMBER/comments in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are used to separate the untrusted comment text from the agent's internal task instructions.
  • Capability inventory: The skill possesses the ability to spawn sub-agents (Task general-purpose(comment)), write to the filesystem (docs/conventions/), and perform git operations (git add, git commit, git push).
  • Sanitization: There is no evidence of sanitization or filtering of the comment content before it is passed to the sub-agent task environment.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands through the GitHub CLI (gh) and Git to manage PR status and update documentation.
  • Evidence: Commands such as gh pr status, gh pr view, and gh api are used to retrieve metadata, and git commit is used to persist changes to the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 04:37 AM