create-pr
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- Command Execution: The skill utilizes standard Git commands and the GitHub CLI (gh) to automate branch management and pull request creation. This is consistent with its intended purpose as a developer productivity tool.\n- Sensitive Information Handling: The instructions correctly guide the user to manage sensitive credentials, such as GitHub Personal Access Tokens and Azure DevOps PATs, as pipeline variables within the Azure DevOps environment. This aligns with security best practices for secret management by avoiding hardcoded credentials.\n- Trusted External References: The skill references official repositories and pipelines within the Microsoft organization on GitHub and Azure DevOps. These sources are consistent with the vendor's established infrastructure and development workflows.
Audit Metadata