get-pr-comments
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill contains only natural language text in the SKILL.md file. It does not include any scripts, executable binaries, or command-line instructions.- [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it processes pull request comments from an external source. Ingestion points: Pull request comments (Workflow step 2 in SKILL.md). Boundary markers: Absent; the skill does not instruct the agent to ignore instructions embedded in the comments. Capability inventory: None; the skill does not define tool usage or dangerous operations. Sanitization: Absent; the skill performs no filtering or validation on ingested text.- [SAFE]: No obfuscation, base64 encoding, hardcoded credentials, or persistence mechanisms were identified in the metadata or instructional content.
Audit Metadata