pr-auto-improve

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for advisory code analysis with a mandatory human-in-the-loop approval process for all modifications.
  • [PROMPT_INJECTION]: The skill processes untrusted pull request diffs, presenting a potential indirect prompt injection surface.
  • Ingestion points: PR diffs fetched via gh pr diff in SKILL.md.
  • Boundary markers: The process is advisory-only and does not automatically execute code or commands from the PR diff.
  • Capability inventory: The skill uses mgr-gitnerd for git operations and triggers external expert agents for analysis; changes require user approval before commitment.
  • Sanitization: The mandatory user review and 'Apply improvements?' prompt serve as a validation layer for all suggested changes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — pr-auto-improve