open-pr
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [Containerized Command Execution]: The skill executes shell operations using a dedicated container backend, which provides isolation for cloning repositories, running builds, and executing tests.
- [Secure Dependency Management]: It utilizes the frozen-lockfile parameter during installation to ensure that the development environment remains consistent and protected against unauthorized dependency modifications.
- [Official Deployment Integration]: The process employs established deployment tools to host temporary demos, allowing for the verification of code changes in a controlled environment.
- [External Data Processing Surface]: The skill ingests data from external issues and comments via repository management tools to guide its resolution process. This ingestion is managed by the logic to maintain focus on the specific assigned task while providing the necessary context for the fix.
Audit Metadata