dev-pr
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to interact with the local operating system by executing Git commands (
git status,git branch,git remote,git fetch,git rebase,git push) and forge CLI tools such as GitHub'sghor GitLab'sglab. These commands are standard for the described purpose of publishing feature branches for review. - [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface because it processes untrusted data from the repository context.
- Ingestion points: Untrusted data enters the agent context via
git status,git remote,git diffduring conflict resolution, and output from forge CLI tools (which may include external comments or PR descriptions). - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the skill instructions.
- Capability inventory: The skill has the capability to execute shell commands, perform network pushes to Git remotes, and create/update PRs via APIs.
- Sanitization: The skill does not mention sanitizing or escaping the data retrieved from the Git repository or forge tools before using it to generate PR descriptions or perform subsequent actions.
Audit Metadata