mcore-split-pr
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests potentially untrusted data from GitHub pull requests, including titles, bodies, and file diffs, which are processed by the agent.\n
- Ingestion points: Data is fetched from the NVIDIA/Megatron-LM repository using the
gh pr viewandgh pr diffcommands as specified inSKILL.md.\n - Boundary markers: The skill instructs the agent to "Wait for user approval before execution," serving as a human-in-the-loop review mechanism.\n
- Capability inventory: The skill uses
git applyto modify the local filesystem and theghCLI to create draft pull requests and edit PR bases inSKILL.md.\n - Sanitization: There are no explicit instructions in
SKILL.mdto sanitize or escape pull request content before it is interpolated into the workflow.\n- [COMMAND_EXECUTION]: The skill uses the GitHub CLI (gh) andgitto automate PR management tasks.\n - Usage: Commands such as
gh pr view,gh pr diff,gh api user,git diff,git apply, andgh pr editare employed to analyze and split pull requests.\n - Context: These operations are restricted to the vendor's repository (
NVIDIA/Megatron-LM) and the user's fork, following standard development practices.\n- [EXTERNAL_DOWNLOADS]: The skill references official GitHub documentation for stacked PR workflows.\n - Evidence: The skill points to
https://docs.github.com/en/pull-requests/how-tos/create-pull-requests/creating-stacked-pull-requestsinSKILL.md.\n - Context: This is a reference to a trusted service (GitHub) provided for instructional purposes and does not involve automated code downloads.
Audit Metadata