run-pre-pr-checks

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill discovers and executes local commands such as npm run lint, pytest, and go test by inspecting project files like package.json and Makefile. This is the core functionality intended for pre-PR validation.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx for tools like prettier and knip, and runs npm audit. These commands may interact with the official npm registry to fetch or check packages, which is standard behavior for Node.js development.
  • [PROMPT_INJECTION]: The skill parses project configuration files (package.json, Makefile, CI workflows) to determine which commands to run. This creates an indirect prompt injection surface where repository content could influence the agent's actions, though it is limited to the project's own defined validation scripts. Ingestion points: package.json, Makefile, CI workflows. Capability inventory: shell command execution. Sanitization: None. Boundary markers: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:13 AM
Security Audit — agent-trust-hub — run-pre-pr-checks