airflow-pr-draft-summary
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run the
prek installcommand to configure git hooks. While this is presented as a standard setup step for the project, it involves the execution of a local binary with system-level impact.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from pull requests and issues to generate summaries and file content, creating a vulnerability surface.\n - Ingestion points: Pull request descriptions, titles, and issue content are used as inputs for drafting text in
SKILL.md.\n - Boundary markers: The instructions do not define clear delimiters or specify that the agent should ignore instructions embedded within the processed pull request or issue data.\n
- Capability inventory: The skill uses shell commands like
echoto write newsfragment files to the local file system based on pull request metadata.\n - Sanitization: There is no explicit requirement to sanitize variables such as
{PR_NUMBER}or the descriptive text before they are interpolated into the shell commandecho "Brief description" > airflow-core/newsfragments/{PR_NUMBER}.rst. This could potentially be exploited for path traversal or argument injection if a pull request is assigned a malicious identifier or contains specially crafted content.
Audit Metadata