github-pr-proof-assets
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill makes appropriate use of developer tools (
gh,curl,ffmpeg,ffprobe,jq) to verify repository context and process media files. It properly handles shell variables by usingjqfor URL encoding, which mitigates the risk of command injection through malformed filenames. - [DATA_EXFILTRATION]: Network operations are restricted to well-known GitHub domains (
github.comanduploads.github.com). The skill includes explicit security warnings to prevent the exposure or storage of the GitHub authentication token in logs or configuration files, ensuring it is only expanded in-memory during specific requests. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with local files and external API responses.
- Ingestion points: Local media assets and response bodies from GitHub API calls referenced in
SKILL.md. - Boundary markers: While there are no specific prompt delimiters for the data content, the instructions mandate a manual review of the final comment body-file before execution of the
gh commentcommand. - Capability inventory: The skill uses
curlandghfor network communication andffmpegfor file processing and writing. - Sanitization: The skill employs
jqto sanitize and encode external data strings before they are interpolated into shell commands.
Audit Metadata