skills/yistc/skills/yistc-pr-merge/Gen Agent Trust Hub

yistc-pr-merge

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) and standard git commands to perform pull request merges, pull updates to the local environment, and manage branch cleanup (both local and remote). This behavior is explicitly defined in the skill's purpose.
  • [SAFE]: No indicators of malicious activity such as prompt injection, code obfuscation, hardcoded credentials, or unauthorized data exfiltration were found during the analysis.
  • [SAFE]: While the skill interacts with external platforms (GitHub and Notion) and processes PR data, it operates within a controlled workflow that requires user confirmation, mitigating the risk of indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 04:57 AM
Security Audit — agent-trust-hub — yistc-pr-merge