create-pr-for-branch
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
prepublishOnlyscript defined in the local repository's configuration.\n- [DYNAMIC_EXECUTION]: The skill dynamically identifies and runs commands defined inpackage.jsonat runtime, which allows for arbitrary command execution based on the content of the repository.\n- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through project configuration files.\n - Ingestion points: The skill reads
package.json(SKILL.md) to detect and execute theprepublishOnlyscript.\n - Boundary markers: The instructions include a 'human-only' directive and require explicit confirmation if the skill is triggered by another agent skill.\n
- Capability inventory: The skill can execute arbitrary shell scripts via the project's lifecycle hooks and perform GitHub operations using the
ghCLI tool.\n - Sanitization: There is no automated sanitization of the script content; the skill relies on the human user to provide oversight and confirmation.
Audit Metadata