skills/mblode/agent-skills/pr-creator/Gen Agent Trust Hub

pr-creator

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from repository-controlled files and history to generate Pull Request descriptions, creating a surface for indirect instruction injection.
  • Ingestion points: The skill reads pull_request_template.md from the repository (multiple possible paths including .github/) and commit messages via git log to draft PR titles and bodies.
  • Boundary markers: There are no explicit delimiters or warnings to ignore instructions embedded within the ingested data, although the skill enforces a strict output format (one-paragraph body, specific title rules) which provides some natural filtering.
  • Capability inventory: The skill uses the GitHub CLI (gh) and Git to perform operations including git push, gh pr create, and gh pr edit based on the generated content.
  • Sanitization: The instructions do not specify any sanitization, escaping, or filtering of commit messages or template content before interpolation into the final shell commands or PR body.
  • [COMMAND_EXECUTION]: The skill extensively utilizes shell commands to manage repository state and interact with the GitHub API.
  • Automated Workflow: It automates complex Git operations such as git rebase -i --autosquash (using GIT_SEQUENCE_EDITOR=true to bypass interactive prompts) and git reset --soft for history restructuring.
  • Network Interaction: It executes git push and gh pr commands to send data to GitHub servers.
  • Safety Guardrails: The skill includes best-practice safety checks, such as capturing the tree hash (git rev-parse HEAD^{tree}) to verify code integrity after history rewrites and recommending git push --force-with-lease over standard force-pushes.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:50 PM
Security Audit — agent-trust-hub — pr-creator