mcore-split-pr

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests potentially untrusted data from GitHub pull requests, including titles, bodies, and file diffs, which are processed by the agent.\n
  • Ingestion points: Data is fetched from the NVIDIA/Megatron-LM repository using the gh pr view and gh pr diff commands as specified in SKILL.md.\n
  • Boundary markers: The skill instructs the agent to "Wait for user approval before execution," serving as a human-in-the-loop review mechanism.\n
  • Capability inventory: The skill uses git apply to modify the local filesystem and the gh CLI to create draft pull requests and edit PR bases in SKILL.md.\n
  • Sanitization: There are no explicit instructions in SKILL.md to sanitize or escape pull request content before it is interpolated into the workflow.\n- [COMMAND_EXECUTION]: The skill uses the GitHub CLI (gh) and git to automate PR management tasks.\n
  • Usage: Commands such as gh pr view, gh pr diff, gh api user, git diff, git apply, and gh pr edit are employed to analyze and split pull requests.\n
  • Context: These operations are restricted to the vendor's repository (NVIDIA/Megatron-LM) and the user's fork, following standard development practices.\n- [EXTERNAL_DOWNLOADS]: The skill references official GitHub documentation for stacked PR workflows.\n
  • Evidence: The skill points to https://docs.github.com/en/pull-requests/how-tos/create-pull-requests/creating-stacked-pull-requests in SKILL.md.\n
  • Context: This is a reference to a trusted service (GitHub) provided for instructional purposes and does not involve automated code downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:25 AM
Security Audit — agent-trust-hub — mcore-split-pr