yistc-pr-merge
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (
gh) and standardgitcommands to perform pull request merges, pull updates to the local environment, and manage branch cleanup (both local and remote). This behavior is explicitly defined in the skill's purpose. - [SAFE]: No indicators of malicious activity such as prompt injection, code obfuscation, hardcoded credentials, or unauthorized data exfiltration were found during the analysis.
- [SAFE]: While the skill interacts with external platforms (GitHub and Notion) and processes PR data, it operates within a controlled workflow that requires user confirmation, mitigating the risk of indirect prompt injection.
Audit Metadata