publish
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates and instructions for the agent to execute
gitandgh(GitHub CLI) commands. These operations are standard for the skill's purpose of managing code branches and publishing pull requests. The process is designed to be interactive, requiring user confirmation for all major actions. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes data from git commits, diffs, and external issue trackers (Linear/GitHub) to generate pull request titles and bodies. The risk is mitigated by a mandatory 'Draft and Publish' phase where the agent must present the generated content for human review and approval before final submission.
Audit Metadata