create-pr
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands via the
Bashtool to manage version control and interact with GitHub. - The skill is authorized to use
git status,git diff,git log,git rev-parse,git push, andgh pr create. - These tools are aligned with the stated purpose of automating pull request creation and are used to gather metadata and push code changes.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository's history and current diffs, creating an attack surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through the output of
git diffandgit log(SKILL.md). - Boundary markers: No specific delimiters or instructions are provided to the agent to treat content within the diffs as data rather than instructions.
- Capability inventory: The skill possesses write capabilities including pushing to remote branches (
git push) and creating pull requests (gh pr create) (SKILL.md). - Sanitization: No escaping, validation, or filtering is performed on the content retrieved from the Git history before the agent processes it.
- Note: While the surface exists, this is a standard risk for tools that analyze source code.
Audit Metadata