github-reply
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
pbcopycommand to copy the generated response to the system clipboard. This is a standard operation for the skill's primary functionality. - [SAFE]: The skill's instructions focus on tone, style, and maintainer etiquette. No evidence of prompt injection, data exfiltration, or obfuscation was found. The URLs present are plain-text links to YouTube (a well-known service) and serve as documentation references.
- [SAFE]: While the skill ingests untrusted data from GitHub pull requests and issues (an indirect prompt injection surface), the output is intended for the user's clipboard for manual review before submission, which mitigates the risk of automated malicious actions.
Audit Metadata