User-controlled placeholder is embedded directly into generated source code.
Critical
- Code
- suspicious.generated_source_template_injection
- Location
- SKILL.md:123
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an instruction-only workflow for pushing stacked git branches and opening draft GitHub PRs, with no hidden execution or unrelated data access found.
Install only if you want an agent-assisted workflow that can push stack branches and create GitHub PRs in the current repository. Review the branch prefix, base branch, and generated PR text before allowing the commands to run.
Detected: suspicious.generated_source_template_injection