github-pr-issues

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data from GitHub, creating a surface for indirect prompt injection.\n
  • Ingestion points: PR descriptions, issue comments, and review responses (SKILL.md).\n
  • Boundary markers: The instructions lack delimiters to separate user content from agent instructions.\n
  • Capability inventory: Activities include labeling, issue state management, and comment responses.\n
  • Sanitization: No sanitization steps are defined for handling external data.\n- [NO_CODE]: This skill is entirely instructional and does not contain any executable scripts, code, or external package dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 09:44 AM
Security Audit — agent-trust-hub — github-pr-issues