pm-pr-workflow
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the shell command
git config user.emailto determine the identity of the current user for internal workflow routing logic. - [PROMPT_INJECTION]: The skill implements a hardcoded authorization rule that allows the user
bobmatnyc@users.noreply.github.comto bypass branch protection and push directly to the main branch. This represents a logic-based bypass instruction. - [PROMPT_INJECTION]: The pull request delegation workflow interpolates several variables (
{summary},{file_list},{test_status},{qa_evidence}) into instructions for theversion-controlagent. This creates a surface for indirect prompt injection. \n - Ingestion points: Variables
{summary},{file_list},{test_status}, and{qa_evidence}inSKILL.md. \n - Boundary markers: Absent; there are no delimiters or specific instructions to the agent to disregard embedded instructions within the interpolated text. \n
- Capability inventory: The skill delegates tasks to a
version-controlagent that can create branches, push code, and create pull requests. \n - Sanitization: None; the skill does not perform validation or sanitization on the external content before it is interpolated into the agent task.
Audit Metadata