github-issue-to-pr
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The automation script (
scripts/main.py) performs standardgitoperations such as cloning, committing, and pushing usingsubprocess.run. These operations are limited to a controlled workspace and are essential for the skill's primary function of pull request automation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issue descriptions and discussions (ingestion point:
scripts/main.py,_build_implementation_prompt). It implements robust boundary markers and explicit instructions to the agent to ignore any malicious instructions embedded in the issues. Capabilities like file access and network operations are scoped specifically to the task, and the agent fetches data using official tools rather than receiving raw input in the prompt. Sanitization is handled during setup usingjson.dumpsfor configuration parameters. - [DYNAMIC_EXECUTION]: During setup, the agent generates a customized automation script by substituting specific configuration constants in
scripts/main.py. This dynamic generation is conducted safely usingjson.dumpsfor string literals to prevent command injection during the setup phase. - [SAFE]: The skill manages a
GITHUB_PERSONAL_ACCESS_TOKENfor repository access but mitigates risks by retrieving the token from a secure internal secret store, redacting it in logs, and only forwarding it to the sub-agent conversation based on an explicit, user-defined allow-list.
Audit Metadata