social-copy
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from multiple external sources, which could be leveraged to influence the agent's output via hidden instructions.
- Ingestion points: The agent reads pull request descriptions, review comments, commit messages, git logs, and marketing briefs as defined in Phase 1: Discovery of SKILL.md.
- Boundary markers: There are no explicit instructions within the skill to use delimiters or specific prompt instructions to ignore embedded commands when analyzing external data.
- Capability inventory: The skill has the capability to execute 'gh' and 'git' commands for context gathering and performs file system writes to save the final social copy (Phase 5: Output).
- Sanitization: No sanitization or validation logic is specified for the content retrieved from these external sources.
- [COMMAND_EXECUTION]: The skill executes standard development tools to perform its intended function.
- Evidence: It utilizes commands such as 'gh pr view', 'gh pr diff', 'git diff', and 'git log' to extract technical context for generating platform-specific copy.
Audit Metadata