draft-pr

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs standard local file system operations to read a template and list files in the sandbox directory, which are necessary for its stated PR-drafting function.
  • [SAFE]: No remote code execution patterns, external dependencies, or network-based exfiltration attempts were detected.
  • [SAFE]: The skill does not access sensitive credentials, environment variables, or restricted system paths.
  • [SAFE]: The inclusion of metadata fields and comments simulating organizational approval is transparently part of the skill's simulated context and does not present a security risk.
  • [SAFE]: While the skill processes filenames from the sandbox directory, which is a potential surface for indirect prompt injection, the impact is negligible given the simple utility and absence of high-privilege capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 03:56 PM
Security Audit — agent-trust-hub — draft-pr