describe-pr
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to identify and run commands found within the 'How to verify it' section of a repository's PR template (e.g., 'make check test'). This capability allows for the execution of arbitrary shell commands if a repository's template file is malicious or compromised.
- [DYNAMIC_EXECUTION]: The skill executes a local shell script located at '$CLAUDE_PROJECT_DIR/.claude/scripts/aggregate-reasoning.sh'. This relies on the existence and safety of scripts within specific environment-defined paths.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from PR diffs and commit histories to generate output, which could be exploited by embedding malicious instructions in the code or commit messages. 1. Ingestion points: PR diffs via 'gh pr diff', commit history via 'gh pr view', and local reasoning files. 2. Boundary markers: Absent; no instructions are provided to distinguish data from agent instructions. 3. Capability inventory: Shell execution via 'bash', arbitrary command execution from templates, and PR modification via 'gh pr edit'. 4. Sanitization: No sanitization of ingested PR content is performed.
Audit Metadata