create-pr

Fail

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's workflow for generating a PR description (Step 5) uses the eval command to execute a git diff command string. The variables $BASE_BRANCH and $GIT_DIFF_EXCLUDES (which is built from the --exclude flag) are interpolated into the command string without adequate sanitization or safe argument handling. This creates a significant command injection vulnerability; an attacker could provide a malicious branch name or exclusion path containing shell metacharacters (e.g., ;, &, |, or backticks) to execute arbitrary code on the host system.
  • [DATA_EXFILTRATION]: The skill interacts with the Bitbucket REST API using curl, passing the BITBUCKET_USERNAME and BITBUCKET_APP_PASSWORD environment variables for authentication. While these credentials are used for the skill's stated purpose of creating pull requests, handling and transmitting sensitive credentials via environment variables and network requests to an external API (api.bitbucket.org) represents a potential exfiltration vector if compromised.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its use of an 'Explore' subagent to summarize git diff output. Malicious instructions embedded within the code being analyzed (such as in comments) could influence the subagent's summary, which is then incorporated into the final PR description.
  • Ingestion points: The git diff output is captured in a temporary patch file (.agents/state/pr-diff-*.patch) and read by the Explore subagent.
  • Boundary markers: The subagent prompt in references/pr-body-summariser-prompt.md provides rules for the AI but lacks robust delimiters to separate the untrusted diff content from the system instructions.
  • Capability inventory: The skill has the ability to execute git commands, perform network requests to hosting providers, and interact with Jira via Atlassian MCP tools.
  • Sanitization: There is no evidence of sanitization or validation performed on the diff content before it is passed to the AI subagent for summarization.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — create-pr