create-pr

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard shell commands using git and gh (GitHub CLI) to perform branch management and pull request creation. These are standard operations for the skill's described purpose.
  • [CREDENTIALS_UNSAFE]: The instructions include a specific safety check in Step 5 to prevent the staging of secrets, .env files, or private keys, reducing the risk of accidental data exposure.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads .github/pull_request_template.md to format the PR body. While this involves processing untrusted repository data, the skill follows a strict internal logic that minimizes risk. Ingestion points: Reads repository PR templates in SKILL.md (Step 3). Boundary markers: None explicitly defined for the template content. Capability inventory: Branch manipulation, file diffing, and PR creation via git and gh in SKILL.md (Steps 1, 2, 4, 5, 6, 8). Sanitization: No specific sanitization or escaping of the template markdown content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — create-pr