github-issue-to-pr

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The automation script (scripts/main.py) performs standard git operations such as cloning, committing, and pushing using subprocess.run. These operations are limited to a controlled workspace and are essential for the skill's primary function of pull request automation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issue descriptions and discussions (ingestion point: scripts/main.py, _build_implementation_prompt). It implements robust boundary markers and explicit instructions to the agent to ignore any malicious instructions embedded in the issues. Capabilities like file access and network operations are scoped specifically to the task, and the agent fetches data using official tools rather than receiving raw input in the prompt. Sanitization is handled during setup using json.dumps for configuration parameters.
  • [DYNAMIC_EXECUTION]: During setup, the agent generates a customized automation script by substituting specific configuration constants in scripts/main.py. This dynamic generation is conducted safely using json.dumps for string literals to prevent command injection during the setup phase.
  • [SAFE]: The skill manages a GITHUB_PERSONAL_ACCESS_TOKEN for repository access but mitigates risks by retrieving the token from a secure internal secret store, redacting it in logs, and only forwarding it to the sub-agent conversation based on an explicit, user-defined allow-list.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — github-issue-to-pr