pr-mr

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Structured Command Execution: The skill performs repository operations using local tools like git and authenticated provider CLIs (e.g., GitHub or GitLab CLI). It implements a notable security practice by utilizing temporary files for multi-line inputs (like PR descriptions) rather than shell interpolation, which effectively mitigates common shell-injection vulnerabilities.
  • Indirect Prompt Injection Surface: As the skill reads untrusted data from the repository (such as file contents, Git logs, and diffs) to help generate titles and summaries, there is an inherent risk of indirect prompt injection where malicious content in a branch could influence the agent's behavior.
  • Ingestion points: Reads file contents (specifically index.mdx titles), git diff outputs, and git log entries from the current branch.
  • Boundary markers: The skill does not explicitly define delimiter boundaries when incorporating repo data into the prompt context.
  • Capability inventory: Possesses capabilities to read files, execute shell-based repository commands, and interact with remote hosting services via CLI.
  • Sanitization: The skill mitigates risks by stripping constant prefixes from product names, using file-based inputs for large text blocks, and providing explicit instructions to maintain factual, diff-based summaries.
  • Data Leakage Mitigation: The instructions include clear and explicit prohibitions against including private information, secrets, internal URLs, or credentials in public PR/MR comments or descriptions, which is a key security-positive pattern for open-source contributions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:04 PM
Security Audit — agent-trust-hub — pr-mr