pull-request
Warn
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands via
gitandgh(GitHub CLI). The workflow for creating a pull request uses a command substitution with a heredoc:$(cat <<'EOF' <description> EOF). This pattern is vulnerable to command injection if the LLM-generated description contains the string 'EOF'. An attacker could embed this delimiter in commit messages or code changes to terminate the heredoc and execute arbitrary shell commands in the agent's environment.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it summarizes untrusted data from the repository history.\n - Ingestion points: Outputs from
git log --oneline main...HEADandgit diff main...HEADinSKILL.mdare processed by the agent.\n - Boundary markers: None; the skill lacks delimiters or explicit instructions to the agent to ignore instructions embedded within the git data.\n
- Capability inventory: The skill has access to network and repository write operations through
git pushandgh pr create.\n - Sanitization: None; data from the repository is passed directly into the generation process and subsequently into shell commands without validation or escaping.
Audit Metadata