stacked-pr-decomposition

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard local tools including git and the GitHub CLI (gh) for branch management and PR creation. It also mentions running project-specific tests and builds, which is expected for development tasks.
  • [PROMPT_INJECTION]: The skill involves analyzing repository content (code changes and commits) to plan the PR stack. While this is an indirect ingestion surface, it is a primary requirement for the skill's functionality.
  • Ingestion points: Reads diffs and commit history from the user's active Git branch.
  • Boundary markers: No specific delimiters are provided for code analysis, but the agent's focus is on structural organization.
  • Capability inventory: Access to git, gh, and local build/test environments.
  • Sanitization: Not applicable as the output is intended for human-reviewed PR descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 08:15 PM
Security Audit — agent-trust-hub — stacked-pr-decomposition