branch-finalization
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs local command execution using standard development tools such as
npm,cargo,pytest, andgofor testing, andgitandghfor source control management. These actions are restricted to the intended purpose of verifying code quality and managing branch lifecycle. - [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from test suite outputs and git commit history (Ingestion points: SKILL.md Step 1, Step 2, and Step 4). This data is interpolated into the agent's context and used to generate Pull Request descriptions. The skill uses shell heredocs with quoted delimiters (
cat <<'EOF') to prevent immediate shell expansion of content (Boundary markers), although it does not specify explicit sanitization logic for the processed text. The agent's capabilities are limited to standard development operations (Capability inventory:git,npm,gh).
Audit Metadata