skills/timschoch/mattpocock-skills/pr/Gen Agent Trust Hub

pr

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown instructions and formatting templates. It does not include any executable scripts, command execution patterns, or network requests. Analysis of the provided files confirms the skill is focused solely on text generation for developer workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data, such as project-specific terminology and code diffs, to populate the PR template. While this is a data ingestion surface, the risk is negligible as the skill defines no functional capabilities (like file writing or API calls) that could be abused via injected instructions. Ingestion points: User-provided code diffs and the GLOSSARY.md file mentioned in instructions. Boundary markers: None explicitly defined in the instructions. Capability inventory: No tools, subprocesses, or network operations are enabled or defined. Sanitization: None present in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 02:52 AM