respond-to-pr-comments-in-blocklist

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes Pull Request comments fetched from GitHub. These comments are untrusted external data and could contain indirect prompt injection attacks intended to override the agent's instructions or behavior.
  • Ingestion points: Pull Request comments, review bodies, and thread replies are fetched using the "gh" CLI and loaded into the agent's context as described in SKILL.md.
  • Boundary markers: The instructions do not specify the use of clear boundary markers or delimiters when presenting the untrusted comment content to the agent, which increases the risk of the agent misinterpreting the comment content as instructions.
  • Capability inventory: The agent has the ability to modify local source code files via "git", execute shell commands, and post content back to GitHub via the "gh" CLI.
  • Sanitization: The skill uses safe practices for shell command execution, such as writing comment bodies to temporary files and using the "--input" or "--body-file" flags with the GitHub CLI to avoid shell injection vulnerabilities.
  • [COMMAND_EXECUTION]: The skill uses several command-line tools including "git", "gh", "python3", "mktemp", and "cat". These are used to interact with the local repository and the GitHub API. The usage is consistent with the skill's stated purpose of managing PR reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 01:56 AM
Security Audit — agent-trust-hub — respond-to-pr-comments-in-blocklist