pr-draft-summary
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions specify several Git commands to be executed automatically to collect context:
git rev-parse,git status,git ls-files,git diff,git merge-base, andgit log. These are standard read-only operations used to gather information about the current branch and working directory state for PR summarization. - [INDIRECT_PROMPT_INJECTION]: The skill acts on untrusted data from the repository, specifically code diffs, file paths, and commit messages, to generate summaries. While this represents a potential surface for indirect prompt injection (where malicious content in a diff could influence the agent's summary), the risk is inherent to the skill's primary purpose of code analysis.
- Ingestion points: Data enters the context via
git diffoutputs,git logmessages, and file lists inSKILL.md. - Boundary markers: The skill uses a structured Markdown template for the output but does not explicitly define delimiters for the input data.
- Capability inventory: The skill uses Git commands for data retrieval and suggests a
git checkout -bcommand to the user; it does not perform network operations or file writes automatically. - Sanitization: No specific sanitization or escaping of the Git output is mentioned before interpolation into the PR draft.
Audit Metadata