docs-pr-write
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub Pull Request descriptions, which could contain malicious instructions intended to influence the agent's documentation writing or file modification tasks.
- Ingestion points: Pull request metadata (title, body) is retrieved via
gh pr viewinSKILL.md. - Boundary markers: The instructions do not define boundary markers or include warnings to ignore embedded instructions within the ingested PR data.
- Capability inventory: The skill has access to
Bash,Write,Read, andGreptools, allowing for command execution and filesystem modification. - Sanitization: The skill lacks logic to sanitize or validate the content of the pull request body before it is processed.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to executeghCLI commands to interact with the repository. - Evidence:
SKILL.mdutilizesgh pr viewto extract details from pull requests. - Evidence:
evals/evals.jsondefines severalgh pr listcommands filtered throughjqto identify PRs for testing.
Audit Metadata