resume-from-pr
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub which could contain malicious instructions.
- Ingestion points: Implementation steps in SKILL.md describe fetching PR metadata, body, and comments via 'gh pr view'.
- Boundary markers: The instructions do not define delimiters or specific 'ignore' directives to isolate the retrieved external content from the agent's logic.
- Capability inventory: The skill can execute shell commands like 'git checkout' and 'gh', and it generates development plans.
- Sanitization: No explicit sanitization or validation of the PR content or metadata is performed before use.
- [COMMAND_EXECUTION]: The skill uses local CLI tools ('git', 'gh') to manage the repository. A potential command injection surface exists when the skill uses data retrieved from the GitHub API (such as 'headRefName') as an argument for 'git checkout'.
Audit Metadata