Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe skill facilitates GitHub Pull Request management using the official CLI. It is functional but presents a surface for indirect prompt injection and potential shell command injection if branch names or PR text contain malicious metacharacters.
Socket
warn1 alert: gptSecurity
Snyk
warnRisk: MEDIUM · No issues
Runlayer
pass1 file scanned · No issues
ZeroLeaks
passScore: 93/100 · 2 sections analyzed