skills/damacus/skills/github-pr/Gen Agent Trust Hub

github-pr

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it ingests untrusted data from the local repository (such as file diffs and configuration files) to guide its actions.
  • Ingestion points: The skill reads git status, git diff, and repository-specific configuration files (CI/CD configs, task runners) as described in SKILL.md (Workflow steps 1 and 4).
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used to isolate untrusted file content from the agent's instructions.
  • Capability inventory: The agent has the capability to execute git and gh commands, as well as arbitrary local validation scripts found within the repository.
  • Sanitization: The skill does not describe any sanitization, escaping, or validation of the content read from repository files before using it to determine command execution logic.
  • [COMMAND_EXECUTION]: The skill is designed to identify and run validation commands (tests, linters) defined within the repository's own documentation or configuration files. This results in the execution of arbitrary scripts provided by the codebase.
  • [EXTERNAL_DOWNLOADS]: The skill uses the GitHub CLI (gh) to communicate with GitHub's official services for pushing code and managing pull requests. These interactions target a well-known service and are necessary for the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 12:10 PM
Security Audit — agent-trust-hub — github-pr