pr-creation

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, command injection, or unauthorized data access behaviors were detected. The skill uses standard development tools (git and gh CLI) to perform its stated purpose of pull request management.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from git history and code diffs, which represents an indirect prompt injection surface if the repository content is malicious.\n
  • Ingestion points: git log and git diff outputs are ingested in SKILL.md to generate PR metadata.\n
  • Capability inventory: The agent has access to the Bash tool to execute shell commands and the GitHub CLI.\n
  • Boundary markers: No explicit delimiters or boundary instructions are used when interpolating git output into the agent's reasoning process.\n
  • Sanitization: No sanitization is performed on the git output before it is summarized for the PR body.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 10:17 PM
Security Audit — agent-trust-hub — pr-creation