pr-creator

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, such as credential theft or obfuscation, were detected. The skill functions as a standard automation tool.\n- [COMMAND_EXECUTION]: The skill uses the gh command-line tool and standard shell commands (rm) to manage the pull request lifecycle in SKILL.md. These operations are restricted to the intended purpose of creating pull requests.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing repository-resident pull request templates. 1. Ingestion points: Reads content from files in .github/pull_request_template.md. 2. Boundary markers: Absent. 3. Capability inventory: Uses gh to submit data to GitHub and performs file write/delete in SKILL.md. 4. Sanitization: No explicit validation of template content is performed before interpolation into the PR body.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:19 PM
Security Audit — agent-trust-hub — pr-creator