skills/mpuig/skills/create-pr/Gen Agent Trust Hub

create-pr

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill performs legitimate repository management tasks using verified local tools.
  • [COMMAND_EXECUTION]: The skill executes 'git' and 'gh' commands to interact with the repository history and the GitHub API. It uses security-conscious patterns, such as quoted heredocs ($(cat <<'EOF'...)), to safely handle generated text and prevent shell injection vulnerabilities.
  • [SAFE]: Data ingestion occurs when reading repository diffs and pull request templates. This is necessary for the skill's purpose and the data remains within the local agent context without unauthorized exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 06:26 PM
Security Audit — agent-trust-hub — create-pr