pr-to-ready

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and processes untrusted data from external sources. * Ingestion points: Pull request diffs, commits, reviews, and unresolved threads (identified in steps 1 and 2). * Boundary markers: None present. The instructions do not define clear delimiters for untrusted content or explicitly instruct the agent to disregard instructions embedded in the PR data. * Capability inventory: The agent can write to the filesystem ('Fix actionable items'), execute shell commands ('Run the smallest checks'), and perform network operations via git ('Push'). * Sanitization: No sanitization or validation of the PR content is performed before processing.
  • [COMMAND_EXECUTION]: The skill is designed to execute 'checks' and 'wider checks' which typically involve running scripts or binaries defined within the repository being analyzed. This is an expected behavior for its primary purpose but represents a potential execution vector for malicious code contained in a compromised pull request.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 08:34 AM
Security Audit — agent-trust-hub — pr-to-ready