create-pr
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external git sources, which could be used to influence agent behavior through malicious commit messages or templates. * Ingestion points: Reads commit messages, diff content, and repository PR templates (SKILL.md). * Boundary markers: None present to instruct the agent to ignore embedded instructions in the processed data. * Capability inventory: Executes git branch pushing and pull request creation via platform tools (SKILL.md). * Sanitization: No validation or sanitization of ingested content is performed before generating the PR description.
Audit Metadata