incu-way-prepare-pr

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard development tools such as git and gh (GitHub CLI) to perform version control tasks. These actions are triggered only after explicit user confirmation at several stages, preventing unauthorized code changes or PR creation.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves information from branch names and a local state file (.ways/state.json) to suggest commit messages and pull request descriptions. Although this data originates from the environment, the skill requires the agent to display the proposed text to the user for review and approval before execution, which serves as a effective defense against malicious injection from external data sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:48 PM
Security Audit — agent-trust-hub — incu-way-prepare-pr