pr-craft
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation guide for pull request titles, descriptions, and review practices. It contains no executable scripts, external dependencies, or network-enabled commands.
- [SAFE]: The instructions include a specific safety section titled 'Never in a PR body', which forbids the use of credentials, tokens, secret values, and environment variables, promoting secure development practices.
- [SAFE]: The skill includes defensive instructions to prevent indirect prompt injection by specifying that external PR template content should be treated as layout data rather than directives for the agent.
Audit Metadata