skills/vdustr/skills/vp-pr-briefing/Gen Agent Trust Hub

vp-pr-briefing

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on shell commands using gh and git to fetch Pull Request details, commit messages, and file differences. These commands are used to populate the briefing with context from the repository.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from GitHub PR bodies, comments, and commit messages.\n
  • Ingestion points: Pull request content is retrieved via gh pr view in SKILL.md.\n
  • Boundary markers: The instructions do not define specific delimiters for isolating external content in the briefing output.\n
  • Capability inventory: The agent has access to repository tools (gh, git).\n
  • Sanitization: No specific sanitization or filtering is instructed for the retrieved external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 09:54 AM
Security Audit — agent-trust-hub — vp-pr-briefing