pr-creation
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, command injection, or unauthorized data access behaviors were detected. The skill uses standard development tools (git and gh CLI) to perform its stated purpose of pull request management.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from git history and code diffs, which represents an indirect prompt injection surface if the repository content is malicious.\n
- Ingestion points:
git logandgit diffoutputs are ingested in SKILL.md to generate PR metadata.\n - Capability inventory: The agent has access to the
Bashtool to execute shell commands and the GitHub CLI.\n - Boundary markers: No explicit delimiters or boundary instructions are used when interpolating git output into the agent's reasoning process.\n
- Sanitization: No sanitization is performed on the git output before it is summarized for the PR body.
Audit Metadata