pr-description

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data from the repository environment, creating a surface for indirect prompt injection.\n
  • Ingestion points: The agent is instructed to read repository instructions, pull request templates, code diffs, commit lists, and linked issue specifications (SKILL.md).\n
  • Boundary markers: The instructions lack explicit directives for using delimiters or boundary markers to isolate potentially malicious instructions embedded in the external content.\n
  • Capability inventory: The skill's functionality is limited to generating text summaries and does not explicitly invoke high-privilege tools for file system modification, network communication, or code execution.\n
  • Sanitization: No filtering or sanitization steps are defined for the content ingested from the external repository files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 07:44 PM
Security Audit — agent-trust-hub — pr-description