pr-description

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data which could contain malicious instructions meant to influence the generated PR description.
  • Ingestion points: The skill reads data from git diff, gh pr diff, gh pr view, branch names, commit messages, and linked GitHub issues.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate the untrusted data from the agent's internal instructions or to warn the agent to ignore embedded commands.
  • Capability inventory: The skill possesses the capability to write to the repository using gh pr create and gh pr edit.
  • Sanitization: While the skill emphasizes trimming and editing for clarity, it does not include specific validation or sanitization steps to filter out prompt injection attempts hidden in code comments or commit history.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 06:21 PM
Security Audit — agent-trust-hub — pr-description