resolve-pr-parallel
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub PR comments and reviews, using the content as direct instructions for parallel sub-agents.
- Ingestion points: The skill fetches external content using
gh pr viewandgh api repos/{owner}/{repo}/pulls/PR_NUMBER/commentsinSKILL.md. - Boundary markers: No explicit delimiters or instructions are used to separate the untrusted comment text from the agent's internal task instructions.
- Capability inventory: The skill possesses the ability to spawn sub-agents (
Task general-purpose(comment)), write to the filesystem (docs/conventions/), and perform git operations (git add,git commit,git push). - Sanitization: There is no evidence of sanitization or filtering of the comment content before it is passed to the sub-agent task environment.
- [COMMAND_EXECUTION]: The skill utilizes shell commands through the GitHub CLI (
gh) and Git to manage PR status and update documentation. - Evidence: Commands such as
gh pr status,gh pr view, andgh apiare used to retrieve metadata, andgit commitis used to persist changes to the repository.
Audit Metadata