skills/redis/ioredis/pr-draft-summary/Gen Agent Trust Hub

pr-draft-summary

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions specify several Git commands to be executed automatically to collect context: git rev-parse, git status, git ls-files, git diff, git merge-base, and git log. These are standard read-only operations used to gather information about the current branch and working directory state for PR summarization.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts on untrusted data from the repository, specifically code diffs, file paths, and commit messages, to generate summaries. While this represents a potential surface for indirect prompt injection (where malicious content in a diff could influence the agent's summary), the risk is inherent to the skill's primary purpose of code analysis.
  • Ingestion points: Data enters the context via git diff outputs, git log messages, and file lists in SKILL.md.
  • Boundary markers: The skill uses a structured Markdown template for the output but does not explicitly define delimiters for the input data.
  • Capability inventory: The skill uses Git commands for data retrieval and suggests a git checkout -b command to the user; it does not perform network operations or file writes automatically.
  • Sanitization: No specific sanitization or escaping of the Git output is mentioned before interpolation into the PR draft.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:42 PM
Security Audit — agent-trust-hub — pr-draft-summary