skills/grafana/tempo/docs-pr-write/Gen Agent Trust Hub

docs-pr-write

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub Pull Request descriptions, which could contain malicious instructions intended to influence the agent's documentation writing or file modification tasks.
  • Ingestion points: Pull request metadata (title, body) is retrieved via gh pr view in SKILL.md.
  • Boundary markers: The instructions do not define boundary markers or include warnings to ignore embedded instructions within the ingested PR data.
  • Capability inventory: The skill has access to Bash, Write, Read, and Grep tools, allowing for command execution and filesystem modification.
  • Sanitization: The skill lacks logic to sanitize or validate the content of the pull request body before it is processed.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute gh CLI commands to interact with the repository.
  • Evidence: SKILL.md utilizes gh pr view to extract details from pull requests.
  • Evidence: evals/evals.json defines several gh pr list commands filtered through jq to identify PRs for testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 02:19 AM
Security Audit — agent-trust-hub — docs-pr-write