merge-open-prs

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub Pull Requests, including titles, bodies, comments, and code diffs, which could potentially contain malicious instructions.
  • Ingestion points: Pull request metadata, discussion threads, and diff contents are ingested via gh pr list, gh pr diff, and gh pr checks (SKILL.md, Phase 1 & 2).
  • Boundary markers: The skill includes explicit instructions to treat all PR-related content as untrusted third-party data and specifically forbids obeying instructions found within these sources (SKILL.md, External Side Effects).
  • Capability inventory: The skill possesses the ability to merge branches via gh pr merge, push code fixes via git push (in force mode), and manage CI runs via gh run commands (SKILL.md, Force Execution & Phase 4).
  • Sanitization: A consolidated merge plan is presented to the user for explicit confirmation before any merges occur in the default mode (SKILL.md, Phase 3).
  • [COMMAND_EXECUTION]: The skill executes shell commands using git, gh (GitHub CLI), and jq to perform repository operations.
  • Authorized actions include branch merging, committing narrow fixes to remote branches, and rerunning or cancelling GitHub Action jobs.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with GitHub APIs to retrieve repository information, pull request details, and CI logs.
  • These interactions are performed using the official GitHub CLI and are necessary for the skill's primary function of PR management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — merge-open-prs