improve-pr-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands (git, gh, mktemp) to fetch repository data and manage temporary worktrees. It interpolates user-supplied arguments (PR numbers or URLs) directly into these command strings, which presents a potential command injection surface if the agent does not properly sanitize the inputs.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from pull request diffs, code comments, and project documentation (CONTEXT.md, ADRs).
  • Ingestion points: gh pr view, git diff, and various source code files in the analyzed repository.
  • Boundary markers: None explicitly defined in the execution logic; the agent is instructed to use a specific vocabulary but lacks rigid delimiters for untrusted content.
  • Capability inventory: The skill has the ability to post comments to GitHub PRs (gh pr comment) and modify documentation files in the user's local checkout.
  • Sanitization: There is no explicit sanitization step for the ingested content, though the skill requires a manual 'yes' from the user before posting the final report to the PR.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:38 PM
Security Audit — agent-trust-hub — improve-pr-architecture