T01 · Skill Instruction Hijacking
- Location
SKILL.md:347- Finding
Untrusted GitHub Content Can Hijack Privileged Sub-Agents
- Content
View full analysis
Repository: {SOURCE_REPO} Issue: #{number} Title: {title} URL: {url} Labels: {labels} Body: {body} ``` Review comments are similarly passed to an agent that is instructed to implement them: ```text {json_array_of_actionable_comments} Each comment has: - id: comment ID (for replying) - user: who left it - body: the comment text - path: file path (for inline comments) - line: line number (for inline comments) - diff_hunk: surrounding diff context (for inline comments) - source: where the comment came from (review, inline, pr_body, greptile, etc.) Follow these steps in order: ... 2. UNDERSTAND — Read ALL review comments carefully. Group them by file. Understand what each reviewer is asking for. 3. IMPLEMENT — For each comment, make the requested change: - Read the file and locate the relevant code - Make the change the reviewer requested - If the comment is vague or you disagree, still attempt a reasonable fix but note your concern - If the comment asks for something impossible or contradictory, skip it and explain why in your reply ``` ### Technical Analysis GitHub issue titles, bodies, ...[truncated 2347 chars]- Remediation
View remediation
