pr-triage
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from GitHub Pull Request comments and CI logs, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill runs
kscripts pr-triageto retrieve PR comments, review threads, and CI status summaries into a local artifact (raw_triage_output.md). - Boundary markers: There are no explicit instructions for using delimiters or boundary markers when interpolating this untrusted data into the triage report.
- Capability inventory: The skill has the ability to execute shell commands (
run_command), perform Git operations (git pull,git push), and modify GitHub PRs (gh pr edit). - Sanitization: The instructions do not specify a sanitization process for external content.
- Risk Mitigation: The risk is significantly lowered by explicit instructions to treat all external feedback as unverified claims, a mandatory empirical verification gate (e.g., using
dart analyze), and a requirement for human approval before any implementation steps. - [COMMAND_EXECUTION]: The skill relies on executing various CLI tools to perform its tasks.
- Evidence: It uses
kscripts(a custom utility), standard Git commands, the GitHub CLI (gh), and Dart SDK tools (dart analyze,dart test,dart format). These are standard operational tools for the intended development workflow.
Audit Metadata