pr-to-spec

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Git repositories and GitHub Pull Requests (including code diffs, commit messages, and PR descriptions). The instructions explicitly warn to treat repository references and filenames as untrusted input, acknowledging the inherent security surface when analyzing external content.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute git and pr-to-spec commands for local repository analysis and status checks.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the GitHub API to fetch metadata and diffs for remote Pull Request analysis. This network operation targets a well-known service and is a documented feature of the tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 11:51 AM
Security Audit — agent-trust-hub — pr-to-spec