airflow-pr-draft-summary

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run the prek install command to configure git hooks. While this is presented as a standard setup step for the project, it involves the execution of a local binary with system-level impact.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from pull requests and issues to generate summaries and file content, creating a vulnerability surface.\n
  • Ingestion points: Pull request descriptions, titles, and issue content are used as inputs for drafting text in SKILL.md.\n
  • Boundary markers: The instructions do not define clear delimiters or specify that the agent should ignore instructions embedded within the processed pull request or issue data.\n
  • Capability inventory: The skill uses shell commands like echo to write newsfragment files to the local file system based on pull request metadata.\n
  • Sanitization: There is no explicit requirement to sanitize variables such as {PR_NUMBER} or the descriptive text before they are interpolated into the shell command echo "Brief description" > airflow-core/newsfragments/{PR_NUMBER}.rst. This could potentially be exploited for path traversal or argument injection if a pull request is assigned a malicious identifier or contains specially crafted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:24 AM
Security Audit — agent-trust-hub — airflow-pr-draft-summary