create-pr

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements GitHub pull request automation using standard CLI tools. It follows security best practices for shell scripting, specifically using quoted heredocs ('EOF') when constructing the PR body to prevent unintended variable expansion or command injection during the execution phase. While the skill reads local repository data (git diffs and templates), which represents a potential surface for indirect prompt injection, it does not possess high-risk capabilities that would enable significant exploitation. The use of the GitHub CLI and Git is restricted to the tools specified in the frontmatter configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 10:34 AM
Security Audit — agent-trust-hub — create-pr