apex-tier2
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes standard development tools (npm, pytest, cargo, go) and the GitHub CLI (
gh) to perform code validation and PR management within the local project directory. - [INDIRECT_PROMPT_INJECTION]: The validation scripts parse project configuration files (e.g.,
package.json,pyproject.toml) to determine which commands to run. This ingestion surface is mitigated by the skill's core workflow, which mandates human approval at defined checkpoints before proceeding. - [DYNAMIC_EXECUTION]: The scripts utilize shell evaluation (
evalin Bash andInvoke-Expressionin PowerShell) to dynamically invoke testing and linting tools based on the detected project environment. These commands are constructed from static templates and standard tool names.
Audit Metadata