pm-pr-workflow

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the shell command git config user.email to determine the identity of the current user for internal workflow routing logic.
  • [PROMPT_INJECTION]: The skill implements a hardcoded authorization rule that allows the user bobmatnyc@users.noreply.github.com to bypass branch protection and push directly to the main branch. This represents a logic-based bypass instruction.
  • [PROMPT_INJECTION]: The pull request delegation workflow interpolates several variables ({summary}, {file_list}, {test_status}, {qa_evidence}) into instructions for the version-control agent. This creates a surface for indirect prompt injection. \n
  • Ingestion points: Variables {summary}, {file_list}, {test_status}, and {qa_evidence} in SKILL.md. \n
  • Boundary markers: Absent; there are no delimiters or specific instructions to the agent to disregard embedded instructions within the interpolated text. \n
  • Capability inventory: The skill delegates tasks to a version-control agent that can create branches, push code, and create pull requests. \n
  • Sanitization: None; the skill does not perform validation or sanitization on the external content before it is interpolated into the agent task.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:30 PM
Security Audit — agent-trust-hub — pm-pr-workflow