creating-description-for-gh-pr
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes code diffs and commit logs, which are untrusted data sources that could influence AI behavior.
- Ingestion points: The skill ingests external content via the
git diffandgit logcommands as specified in the analysis section of SKILL.md. - Boundary markers: The instructions lack explicit delimiters or specific guardrails telling the agent to ignore instructions embedded within the diff content or commit messages.
- Capability inventory: The skill executes
gitcommands, writes to a local file (prDescription.md), and suggests performing network-enabled actions via theghCLI tool. - Sanitization: There is no evidence of content sanitization or validation performed on the ingested git data before it is processed by the AI.
- [COMMAND_EXECUTION]: The skill uses standard local commands such as
git diff,git log, andgh pr create. These are legitimate developer tools used within their intended scope for version control and repository management.
Audit Metadata