pr-description
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external repository data, which creates a potential surface for indirect prompt injection attacks where malicious code comments or commit messages could influence the agent's summary.
- Ingestion points: The skill gathers context from the current Git branch, including changed files, diffs, and recent commit history (referenced in Workflow Step 1 and Stacked PRs Step 2).
- Boundary markers: The instructions do not define clear delimiters or provide the agent with guidance to treat the diff content as untrusted data separate from the task instructions.
- Capability inventory: The skill uses
gh pr editto modify pull request metadata on GitHub andgh stack checkoutto change the local environment state. - Sanitization: There are no requirements to sanitize, filter, or validate the content of the diffs or commit messages before they are processed by the model.
Audit Metadata