onequery-pr-body
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
gitandgh(GitHub CLI) for repository and pull request management. These commands are necessary for the skill's stated purpose and are used in a standard manner. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly warns the agent to avoid including absolute paths from the local disk in the PR body. This is a best-practice instruction that protects against accidental leakage of sensitive local system information.
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with existing pull request bodies and conversation context. While this creates a surface for indirect prompt injection, it is a functional requirement for synthesizing PR descriptions and lacks high-risk capabilities like dynamic code evaluation.
- [SAFE]: No obfuscation, malicious persistence mechanisms, or unauthorized network operations were detected. All external resources and repositories are consistent with the author's identity.
Audit Metadata