pr-test-impact-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data such as pull request descriptions and code diffs, which could be used to manipulate the agent's output.
  • Ingestion points: As defined in prompts/pr-test-impact-analysis.md, the agent is instructed to read real materials supplied by the user, including PR description and code diff.
  • Boundary markers: The skill instructions do not specify any unique delimiters or explicit instructions to ignore instructions that might be embedded within the PR content.
  • Capability inventory: Based on the provided files, the skill's capabilities are limited to generating analytical reports in Markdown, JSON, or CSV formats. There are no direct file writes, network operations, or shell command executions defined within the skill's own logic.
  • Sanitization: No sanitization, filtering, or escaping logic for the ingested PR data is present in the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:26 AM
Security Audit — agent-trust-hub — pr-test-impact-analysis