skills/jetbrains/skills/yeet/Gen Agent Trust Hub

yeet

Fail

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The workflow instructs the agent to "run pr-body.md" after writing the PR description to it. Since the PR description is generated by summarizing git diffs, an attacker who can influence the diff (e.g., via a submitted code change) can inject shell commands into the description that the agent will then execute.
  • [REMOTE_CODE_EXECUTION]: The skill explicitly tells the agent to "install dependencies and rerun once" if automated checks fail. This creates a supply chain vulnerability, as the agent may execute malicious installation scripts or download compromised packages defined in the repository's configuration.
  • [PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection because it ingests untrusted git diffs and uses them to generate content that is subsequently executed. There are no boundary markers or instructions to ignore embedded commands in the processed data.
  • [PROMPT_INJECTION]: The metadata fields (author and source URL) claim the skill originates from OpenAI, which contradicts the verified developer context (JetBrains). This misleading information could cause users or systems to misjudge the skill's provenance and security profile.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 18, 2026, 02:45 AM
Security Audit — agent-trust-hub — yeet