qa-pr-requirements-analyzer

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git and gh (GitHub CLI) to retrieve branch information, commit logs, and pull request metadata. These operations are restricted to viewing and diffing repository data as part of its primary function.
  • [EXTERNAL_DOWNLOADS]: Employs the fetch command to retrieve image assets or diagrams referenced in pull request descriptions to facilitate visual requirements analysis.
  • [PROMPT_INJECTION]: The skill processes external, untrusted content from pull requests and tickets, presenting an indirect prompt injection surface.
  • Ingestion points: Pull request titles, descriptions, comments, and content retrieved from linked tickets in Jira, Linear, or GitHub.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when interpolating external content into the agent's context.
  • Capability inventory: The agent has access to shell commands (gh, git) and network requests (fetch).
  • Sanitization: No explicit sanitization or validation of the ingested text is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 06:37 PM
Security Audit — agent-trust-hub — qa-pr-requirements-analyzer