issue-to-pr
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by reading GitHub issue bodies and comments.\n- Ingestion points: SKILL.md specifies discovery steps that involve reading the latest issue body, comments, and linked PR state.\n- Boundary markers: No delimiters or instructions are provided to ensure the agent ignores or isolates instructions embedded within the issue content.\n- Capability inventory: Through its dependencies, the skill has the capability to create branches, implement code changes, and open pull requests.\n- Sanitization: There is no mention of filtering, escaping, or validating the text retrieved from GitHub issues.
Audit Metadata