prepare-paperclip-pr

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's instructions facilitate normal repository maintenance and pull request creation. It utilizes standard command-line tools like git and gh for interacting with the author's own repository (paperclipai/paperclip). The use of logical loops and adherence to specific project guidelines (e.g., commit message metadata, PR file limits) represent legitimate software engineering practices.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources within the repository and tool chain, creating a potential surface for indirect injection.\n
  • Ingestion points: External files (e.g., CONTRIBUTING.md) and tool output (e.g., Greptile feedback, git/gh status).\n
  • Boundary markers: No explicit delimiters or boundary instructions are provided for processed data.\n
  • Capability inventory: The agent has the ability to modify the local file system (git), perform network operations (gh), and call other automation skills (/greploop).\n
  • Sanitization: The instructions do not specify any sanitization or validation of content retrieved from the repository or tools. In the context of a dedicated PR preparation skill, these ingestion points are functional requirements and are considered safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 08:09 AM
Security Audit — agent-trust-hub — prepare-paperclip-pr