docs-pr-check
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub Pull Request descriptions and diffs, which could contain instructions meant to override agent behavior.
- Ingestion points: The skill retrieves PR bodies and code changes using
gh pr viewandgh pr diffinSKILL.md. - Boundary markers: The skill lacks explicit technical delimiters (such as XML tags or JSON structures) for separating ingested content from instructions, relying instead on natural language guidance.
- Capability inventory: The skill has access to
Bash,Read, andGreptools, enabling it to execute local shell commands and read files. - Sanitization: The skill explicitly instructs the agent to ignore directives in the PR body, use the code diff as the authoritative source for classification, and redact any secrets found in diffs using placeholders.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to executegh(GitHub CLI) commands to list, view, and diff Pull Requests within thegrafana/temporepository. This behavior is consistent with the skill's stated purpose of PR assessment.
Audit Metadata