cherry-pr-test
Warn
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill checks out code from GitHub Pull Requests using
gh pr checkoutand subsequently executes it viapnpm debug. Because Pull Requests can be created by external parties, this workflow results in the execution of unverified code on the host system. - [PROMPT_INJECTION]: The skill is exposed to indirect prompt injection through the processing of untrusted PR data. * Ingestion points: PR titles, bodies, and changed files retrieved via
gh pr listandgh pr viewinSKILL.md. * Boundary markers: None; the skill does not use delimiters or instructions to ignore embedded commands within the PR data. * Capability inventory: The skill can execute shell commands (pnpm,git,pkill), manage processes, and perform browser automation (agent-browser). * Sanitization: No sanitization or validation is performed on the content of the PR before it is used to influence the agent's testing actions. - [COMMAND_EXECUTION]: The skill performs broad process termination using
pkill -fandkill -9on specific ports and process names. While intended for environment cleanup, these operations can affect unrelated system processes.
Audit Metadata