yeet
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external reviewers via PR comments and reviews which could contain malicious instructions.
- Ingestion points: Pull request comments, reviews, and inline threads as described in
SKILL.md. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the skill instructions.
- Capability inventory: Includes file modification, git commits, pushing changes to remote repositories, and GitHub CLI interactions.
- Sanitization: There are no instructions for sanitizing or filtering input from reviewers before the agent acts on it.
- [COMMAND_EXECUTION]: The skill requires and uses Git and the GitHub CLI to perform its core functions of managing branches and PRs.
Audit Metadata