create-pr
Fail
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's workflow for generating a PR description (Step 5) uses the
evalcommand to execute agit diffcommand string. The variables$BASE_BRANCHand$GIT_DIFF_EXCLUDES(which is built from the--excludeflag) are interpolated into the command string without adequate sanitization or safe argument handling. This creates a significant command injection vulnerability; an attacker could provide a malicious branch name or exclusion path containing shell metacharacters (e.g.,;,&,|, or backticks) to execute arbitrary code on the host system. - [DATA_EXFILTRATION]: The skill interacts with the Bitbucket REST API using
curl, passing theBITBUCKET_USERNAMEandBITBUCKET_APP_PASSWORDenvironment variables for authentication. While these credentials are used for the skill's stated purpose of creating pull requests, handling and transmitting sensitive credentials via environment variables and network requests to an external API (api.bitbucket.org) represents a potential exfiltration vector if compromised. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its use of an 'Explore' subagent to summarize
git diffoutput. Malicious instructions embedded within the code being analyzed (such as in comments) could influence the subagent's summary, which is then incorporated into the final PR description. - Ingestion points: The
git diffoutput is captured in a temporary patch file (.agents/state/pr-diff-*.patch) and read by the Explore subagent. - Boundary markers: The subagent prompt in
references/pr-body-summariser-prompt.mdprovides rules for the AI but lacks robust delimiters to separate the untrusted diff content from the system instructions. - Capability inventory: The skill has the ability to execute git commands, perform network requests to hosting providers, and interact with Jira via Atlassian MCP tools.
- Sanitization: There is no evidence of sanitization or validation performed on the diff content before it is passed to the AI subagent for summarization.
Recommendations
- AI detected serious security threats
Audit Metadata