pr-message-writer

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local git commands such as 'git log', 'git diff', and 'git merge-base' to gather context about branch differences and commit history. These operations are standard for a documentation tool and are used solely to generate text descriptions without modifying the system state.- [DATA_EXPOSURE]: The skill reads the contents of the repository to summarize changes, but it includes explicit guidelines and quality checks to ensure that sensitive information like secrets, tokens, or internal credentials are excluded from the final output. The payment card numbers and URLs provided in the reference examples are well-known, public test placeholders for developer use.- [SAFE]: No remote code execution, persistence mechanisms, or unauthorized network operations were detected. All external references are limited to documentation templates and a repository owned by the skill's author.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 02:45 PM
Security Audit — agent-trust-hub — pr-message-writer