create-pr-for-branch

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the prepublishOnly script defined in the local repository's configuration.\n- [DYNAMIC_EXECUTION]: The skill dynamically identifies and runs commands defined in package.json at runtime, which allows for arbitrary command execution based on the content of the repository.\n- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through project configuration files.\n
  • Ingestion points: The skill reads package.json (SKILL.md) to detect and execute the prepublishOnly script.\n
  • Boundary markers: The instructions include a 'human-only' directive and require explicit confirmation if the skill is triggered by another agent skill.\n
  • Capability inventory: The skill can execute arbitrary shell scripts via the project's lifecycle hooks and perform GitHub operations using the gh CLI tool.\n
  • Sanitization: There is no automated sanitization of the script content; the skill relies on the human user to provide oversight and confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:35 PM
Security Audit — agent-trust-hub — create-pr-for-branch