qa-changes
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and interpret untrusted text from Pull Request descriptions, titles, and linked issues to define its QA strategy. A malicious contributor could embed instructions in these fields to manipulate the agent's behavior.
- Ingestion points: Reads PR diffs, titles, and descriptions in Phase 1 (SKILL.md).
- Boundary markers: None explicitly defined to separate PR metadata from instructions.
- Capability inventory: The skill has broad capabilities including shell execution (Phase 2), network operations (Phase 3), and GitHub API usage for reporting (Phase 4).
- Sanitization: No sanitization or validation of the PR text is mentioned.
- [REMOTE_CODE_EXECUTION]: The skill is designed to download and execute code from external Pull Requests. It explicitly commands the agent to install dependencies (e.g., via npm, pip, cargo) and run the application's CLI or servers to verify functionality. This represents an intentional remote code execution surface for untrusted PR code.
- [COMMAND_EXECUTION]: The skill facilitates the execution of various shell commands for environment setup, building projects, and running software as part of the functional verification process.
Audit Metadata