OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn3 providerslatest audit Sep 15, 2026
Independent checks from skills.sh's audit partners.
The skill is structurally safe and properly handles arguments when executing git and GitHub CLI commands, but it exhibits an indirect prompt injection surface because it reads and processes untrusted repository history and code diffs without sanitization or boundary constraints.
Detected behaviors
No alerts
1 issue