pull-request

Warn

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands via git and gh (GitHub CLI). The workflow for creating a pull request uses a command substitution with a heredoc: $(cat <<'EOF' <description> EOF). This pattern is vulnerable to command injection if the LLM-generated description contains the string 'EOF'. An attacker could embed this delimiter in commit messages or code changes to terminate the heredoc and execute arbitrary shell commands in the agent's environment.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it summarizes untrusted data from the repository history.\n
  • Ingestion points: Outputs from git log --oneline main...HEAD and git diff main...HEAD in SKILL.md are processed by the agent.\n
  • Boundary markers: None; the skill lacks delimiters or explicit instructions to the agent to ignore instructions embedded within the git data.\n
  • Capability inventory: The skill has access to network and repository write operations through git push and gh pr create.\n
  • Sanitization: None; data from the repository is passed directly into the generation process and subsequently into shell commands without validation or escaping.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 02:33 PM
Security Audit — agent-trust-hub — pull-request