skills/skcache/prnotes/pr-notes/Gen Agent Trust Hub

pr-notes

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from external sources that may be controlled by an attacker, such as repository diffs, pull request comments, and issue tickets, creating a surface for potential instruction override.
  • Ingestion points: The agent is directed to inspect repository diffs, changed files, logs, metrics, and relevant PR comments as per the instructions in SKILL.md.
  • Boundary markers: The skill lacks instructions for using delimiters or explicit 'ignore embedded instructions' warnings for the ingested repository data.
  • Capability inventory: The skill utilizes repository read access and text generation capabilities to produce documentation.
  • Sanitization: No sanitization, validation, or escaping requirements are specified for the content retrieved from the external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 06:36 AM
Security Audit — agent-trust-hub — pr-notes