skills/dbpolito/skills/get-pr-ready/Gen Agent Trust Hub

get-pr-ready

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external GitHub sources, including PR reviews, inline comments, and CI logs. This data could potentially contain malicious instructions intended to manipulate the agent's behavior.
  • Ingestion points: gh CLI outputs (PR checks, reviews, and threads) in SKILL.md.
  • Boundary markers: No specific delimiters or 'ignore instructions' directives are provided for handling the external content.
  • Capability inventory: The skill has the ability to modify local files, create commits, and push to remote branches.
  • Sanitization: There are no instructions for sanitizing or validating the content retrieved from the PR threads before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:38 PM
Security Audit — agent-trust-hub — get-pr-ready