get-pr-ready
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external GitHub sources, including PR reviews, inline comments, and CI logs. This data could potentially contain malicious instructions intended to manipulate the agent's behavior.
- Ingestion points: gh CLI outputs (PR checks, reviews, and threads) in SKILL.md.
- Boundary markers: No specific delimiters or 'ignore instructions' directives are provided for handling the external content.
- Capability inventory: The skill has the ability to modify local files, create commits, and push to remote branches.
- Sanitization: There are no instructions for sanitizing or validating the content retrieved from the PR threads before processing.
Audit Metadata