pr-creator
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from repository-controlled files and history to generate Pull Request descriptions, creating a surface for indirect instruction injection.
- Ingestion points: The skill reads
pull_request_template.mdfrom the repository (multiple possible paths including.github/) and commit messages viagit logto draft PR titles and bodies. - Boundary markers: There are no explicit delimiters or warnings to ignore instructions embedded within the ingested data, although the skill enforces a strict output format (one-paragraph body, specific title rules) which provides some natural filtering.
- Capability inventory: The skill uses the GitHub CLI (
gh) and Git to perform operations includinggit push,gh pr create, andgh pr editbased on the generated content. - Sanitization: The instructions do not specify any sanitization, escaping, or filtering of commit messages or template content before interpolation into the final shell commands or PR body.
- [COMMAND_EXECUTION]: The skill extensively utilizes shell commands to manage repository state and interact with the GitHub API.
- Automated Workflow: It automates complex Git operations such as
git rebase -i --autosquash(usingGIT_SEQUENCE_EDITOR=trueto bypass interactive prompts) andgit reset --softfor history restructuring. - Network Interaction: It executes
git pushandgh prcommands to send data to GitHub servers. - Safety Guardrails: The skill includes best-practice safety checks, such as capturing the tree hash (
git rev-parse HEAD^{tree}) to verify code integrity after history rewrites and recommendinggit push --force-with-leaseover standard force-pushes.
Audit Metadata