pr-triage
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub Pull Requests via
gh pr view(title and body) andgh pr diff(code changes) as described in SKILL.md. This data is processed by the agent to perform automated triage and 'surface checks', creating a vulnerability where malicious instructions embedded in a PR could influence the agent's output or classification behavior. - Ingestion points: PR title, description, and diff content extracted in Steps 1 and 3.
- Boundary markers: Absent; the instructions do not specify delimiters or prompts to ignore instructions within the ingested data.
- Capability inventory: GitHub CLI (
gh), Git CLI (git), and local file writing to.pr-triage.json. - Sanitization: Absent; there is no mention of filtering or escaping the external content before processing.
- [COMMAND_EXECUTION]: The skill instructions call for the execution of shell commands (
ghandgit) that interpolate values such as the PR number and commit SHAs (last_reviewed_commit). If these variables are derived from untrusted sources without strict validation, they could be leveraged for command injection attacks.
Audit Metadata