pulls
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data from GitHub pull requests, including descriptions, diffs, and review comments. This creates an attack surface where an attacker could embed instructions within a PR to influence the agent's behavior.
- Ingestion points: The skill retrieves PR content, reviews, and linked issues using the
gh pr viewcommand and other git operations (SKILL.md). - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to disregard or isolate embedded directives found within the external PR content.
- Capability inventory: The skill possesses capabilities to perform GitHub mutations via the
ghCLI, including creating, merging, and closing pull requests. It can also chain to other execution-oriented skills such asfix-itormerge-it(SKILL.md, ops.md). - Sanitization: There is no evidence of content filtering, escaping, or sanitization logic applied to the external data before it is interpolated into the agent's context.
Audit Metadata