run-pre-pr-checks
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill discovers and executes local commands such as
npm run lint,pytest, andgo testby inspecting project files likepackage.jsonandMakefile. This is the core functionality intended for pre-PR validation. - [EXTERNAL_DOWNLOADS]: The skill uses
npxfor tools likeprettierandknip, and runsnpm audit. These commands may interact with the official npm registry to fetch or check packages, which is standard behavior for Node.js development. - [PROMPT_INJECTION]: The skill parses project configuration files (
package.json,Makefile, CI workflows) to determine which commands to run. This creates an indirect prompt injection surface where repository content could influence the agent's actions, though it is limited to the project's own defined validation scripts. Ingestion points:package.json,Makefile, CI workflows. Capability inventory: shell command execution. Sanitization: None. Boundary markers: None.
Audit Metadata