skills/tisfeng/skills/submit-pr/Gen Agent Trust Hub

submit-pr

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script invokes local git and gh binaries using subprocess.run with list-based arguments. This ensures that shell execution is disabled, preventing potential command injection attacks from malicious repository input such as branch names or commit messages.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data in the form of repository files, PR templates, and Git commit logs. It securely encapsulates these within literal strings and temporary markdown files without evaluating them as executable code or prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:57 AM
Security Audit — agent-trust-hub — submit-pr