git-remote-pr
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently executes the
gitandgh(GitHub CLI) command-line interfaces to perform repository operations, read configurations, and interact with the GitHub API. - The implementation uses a robust
Invoke-Toolwrapper inscripts/pr-common.ps1that passes arguments as arrays (& $command.Source @Arguments), effectively preventing shell injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The skill interacts with GitHub, a well-known service, to fetch repository metadata, pull request details, and template files.
- These operations are performed via authenticated GitHub CLI calls (
gh api,gh pr) and standard Git commands (git fetch,git ls-remote). - These interactions are transparently documented in the preparation phase and are essential to the skill's primary function.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a processing surface for untrusted data by ingesting Git commit messages and file diffs to generate pull request summaries.
- Ingestion points:
scripts/prepare-pr.ps1reads the output ofgit logandgit diffto collect evidence for the PR body. - Boundary markers: The skill enforces a strict Markdown structure for the generated body using
Assert-PrBodyStructureinscripts/pr-common.ps1, which helps maintain the integrity of the agent's output. - Capability inventory: The skill possesses significant capabilities, including the ability to push commits (
git push) and modify PR metadata (gh pr create/edit). - Sanitization: While the skill performs structural validation, it relies on the underlying LLM's guardrails to handle potentially malicious instructions embedded in commit text. The multi-step 'Prepare -> Plan -> Approve -> Execute' workflow provides a strong human-in-the-loop defense against accidental execution of injected instructions.
Audit Metadata