create-pr
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes standard, well-known CLI tools (
git,gh) for their intended purposes, such as reading repository history and interacting with the GitHub API via an authorized CLI.- [SAFE]: Shell instructions for generating the PR body use quoted here-docs (<<'EOF'), which prevents unintended shell expansion of variables or command substitution, following security best practices for script generation.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local code changes (viagit diffandgit log) to summarize changes. While this represents a theoretical indirect prompt injection surface where code comments or commit messages could attempt to influence the agent's output, the risk is minimal and inherent to the utility's core function of analyzing code.
Audit Metadata