push-and-pr

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the git and gh (GitHub CLI) tools to perform standard version control tasks, including branch validation, remote pushing, and pull request creation.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests data from the local repository that could be controlled by other contributors.
  • Ingestion points: git log, git diff, and .github/PULL_REQUEST_TEMPLATE.md (via file read operations).
  • Boundary markers: Absent; there are no specific delimiters defined to separate the ingested repository content from the agent's instructions.
  • Capability inventory: File system write and delete access (.github/PR_BODY.md), network access via git push, and the ability to create resources on GitHub via gh pr create.
  • Sanitization: No explicit sanitization or validation of the commit history or diff content is specified before the data is summarized into a PR description.
  • [DYNAMIC_EXECUTION]: The skill generates a temporary file (.github/PR_BODY.md) to store the generated pull request description before passing it to the GitHub CLI. This approach is used as a safety measure to prevent shell command failures when handling complex markdown strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — push-and-pr