skills/chrislacey89/skills/pre-merge/Gen Agent Trust Hub

pre-merge

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted input from GitHub issues and PR diffs, creating a surface for indirect prompt injection.
  • Ingestion points: GitHub issue bodies are fetched using gh issue view and pull request diffs using gh pr diff (SKILL.md, Phase 1).
  • Boundary markers: The skill does not implement explicit boundary markers or instructions to ignore embedded directives when processing external content.
  • Capability inventory: The skill has the capability to create and edit pull requests and execute various shell commands via the GitHub CLI.
  • Sanitization: There is no evidence of explicit validation or sanitization of the content retrieved from GitHub before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 04:59 PM
Security Audit — agent-trust-hub — pre-merge