pr-description

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git log and git diff to analyze repository state and uses gh pr list, gh pr create, and gh pr edit to communicate with GitHub API via the CLI.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an injection surface by summarizing untrusted repository data and posting it to GitHub without human approval.
  • Ingestion points: Ingests data from git log, git diff, commit messages, and branch names as specified in SKILL.md.
  • Boundary markers: The skill does not use specific delimiters or instructions to treat the ingested git data as untrusted content.
  • Capability inventory: The skill is capable of performing network operations and modifying remote repository content using gh pr create and gh pr edit commands.
  • Sanitization: There is no evidence of sanitization or filtering of the ingested git strings before they are incorporated into the PR generation process.
  • Risk Factor: The skill includes explicit instructions to "Post immediately" and "Do not wait for approval," which removes the user's opportunity to review the generated content for malicious injections or errors before it is published.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:41 PM
Security Audit — agent-trust-hub — pr-description