branch-finalization

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs local command execution using standard development tools such as npm, cargo, pytest, and go for testing, and git and gh for source control management. These actions are restricted to the intended purpose of verifying code quality and managing branch lifecycle.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from test suite outputs and git commit history (Ingestion points: SKILL.md Step 1, Step 2, and Step 4). This data is interpolated into the agent's context and used to generate Pull Request descriptions. The skill uses shell heredocs with quoted delimiters (cat <<'EOF') to prevent immediate shell expansion of content (Boundary markers), although it does not specify explicit sanitization logic for the processed text. The agent's capabilities are limited to standard development operations (Capability inventory: git, npm, gh).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — branch-finalization