pr-draft

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses several command-line tools to interact with development infrastructure. It executes sf data create record and sf data update record to manage Salesforce GUS work items, git push and git reflog for repository management, and gh pr, gh issue, and gh api graphql for GitHub operations. These commands are used for their intended purpose within a developer workflow, and the skill explicitly mandates user confirmation before any destructive or record-modifying actions are performed.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches content from external sources (GitHub issues and discussions) to analyze and link them to PRs. This represents an attack surface where an attacker could place hidden instructions in an issue body or discussion to influence the agent's behavior during the drafting process. However, the impact is limited as the agent only uses this data to propose links in a text body, and the skill requires the user to review and approve the final PR content and work item updates.
  • Ingestion points: gh issue list (number, title, body, comments) and gh api graphql (fetching discussion titles and bodies).
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the fetched external content.
  • Capability inventory: The skill can write to the filesystem via git, update remote repositories via git push, modify PR reviewers via gh pr edit, and update Salesforce records via sf data.
  • Sanitization: No explicit sanitization or filtering of the fetched GitHub content is described before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:03 AM
Security Audit — agent-trust-hub — pr-draft