describe-pr
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of markdown instructions intended to guide an AI agent in drafting pull request summaries based on code diffs and verification states. It does not include executable code, scripts, or external configuration files.
- [PROMPT_INJECTION]: No evidence of malicious prompt injection, behavior overrides, or safety filter bypass attempts was found. The instructions use standard instructional language and professional terminology.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file paths, credential harvesting patterns, or network exfiltration operations were detected. The skill instructs the agent to read internal project data (diffs, tickets, plans) but does not provide mechanisms to transmit this data to external third parties.
- [REMOTE_CODE_EXECUTION]: The skill does not include any commands for external downloads, package installations, or remote script execution. There are no references to external URLs that would trigger remote code execution.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to ingest external data (diffs and tickets) which represents an attack surface for indirect prompt injection, it does not possess any dangerous capabilities (such as shell execution or network requests) that could be exploited via such an injection. The risk remains negligible.
Audit Metadata