pr-draft
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses several command-line tools to interact with development infrastructure. It executes
sf data create recordandsf data update recordto manage Salesforce GUS work items,git pushandgit reflogfor repository management, andgh pr,gh issue, andgh api graphqlfor GitHub operations. These commands are used for their intended purpose within a developer workflow, and the skill explicitly mandates user confirmation before any destructive or record-modifying actions are performed. - [INDIRECT_PROMPT_INJECTION]: The skill fetches content from external sources (GitHub issues and discussions) to analyze and link them to PRs. This represents an attack surface where an attacker could place hidden instructions in an issue body or discussion to influence the agent's behavior during the drafting process. However, the impact is limited as the agent only uses this data to propose links in a text body, and the skill requires the user to review and approve the final PR content and work item updates.
- Ingestion points:
gh issue list(number, title, body, comments) andgh api graphql(fetching discussion titles and bodies). - Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the fetched external content.
- Capability inventory: The skill can write to the filesystem via
git, update remote repositories viagit push, modify PR reviewers viagh pr edit, and update Salesforce records viasf data. - Sanitization: No explicit sanitization or filtering of the fetched GitHub content is described before it is processed by the LLM.
Audit Metadata