merge-open-prs
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub Pull Requests, including titles, bodies, comments, and code diffs, which could potentially contain malicious instructions.
- Ingestion points: Pull request metadata, discussion threads, and diff contents are ingested via
gh pr list,gh pr diff, andgh pr checks(SKILL.md, Phase 1 & 2). - Boundary markers: The skill includes explicit instructions to treat all PR-related content as untrusted third-party data and specifically forbids obeying instructions found within these sources (SKILL.md, External Side Effects).
- Capability inventory: The skill possesses the ability to merge branches via
gh pr merge, push code fixes viagit push(in force mode), and manage CI runs viagh runcommands (SKILL.md, Force Execution & Phase 4). - Sanitization: A consolidated merge plan is presented to the user for explicit confirmation before any merges occur in the default mode (SKILL.md, Phase 3).
- [COMMAND_EXECUTION]: The skill executes shell commands using
git,gh(GitHub CLI), andjqto perform repository operations. - Authorized actions include branch merging, committing narrow fixes to remote branches, and rerunning or cancelling GitHub Action jobs.
- [EXTERNAL_DOWNLOADS]: The skill communicates with GitHub APIs to retrieve repository information, pull request details, and CI logs.
- These interactions are performed using the official GitHub CLI and are necessary for the skill's primary function of PR management.
Audit Metadata