resume-from-pr

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub which could contain malicious instructions.
  • Ingestion points: Implementation steps in SKILL.md describe fetching PR metadata, body, and comments via 'gh pr view'.
  • Boundary markers: The instructions do not define delimiters or specific 'ignore' directives to isolate the retrieved external content from the agent's logic.
  • Capability inventory: The skill can execute shell commands like 'git checkout' and 'gh', and it generates development plans.
  • Sanitization: No explicit sanitization or validation of the PR content or metadata is performed before use.
  • [COMMAND_EXECUTION]: The skill uses local CLI tools ('git', 'gh') to manage the repository. A potential command injection surface exists when the skill uses data retrieved from the GitHub API (such as 'headRefName') as an argument for 'git checkout'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:13 PM
Security Audit — agent-trust-hub — resume-from-pr