merge-buddy
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely informational and operates in a read-only capacity, fetching pull request metadata without any ability to modify the repository or external state.
- [SAFE]: External data ingestion is limited to GitHub PR information fetched via the official CLI. While this data is technically untrusted, the skill only uses it for classification and reporting, posing no security threat.
- [SAFE]: All command execution is confined to standard, non-destructive tools (gh and jq) with no patterns of sensitive data exfiltration or unauthorized access detected.
Audit Metadata