writing-prs-and-commits

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use gh pr view, gh pr create, gh pr edit, and git commit to automate the creation and updating of pull requests and commit messages. These are standard, legitimate uses of the GitHub and Git CLI tools for the skill's intended purpose.
  • [DATA_EXFILTRATION]: The skill accesses local git repository data and pull request information from GitHub. This data is used solely to generate summaries and is not exfiltrated to unauthorized external domains.
  • [PROMPT_INJECTION]: No malicious patterns, bypass attempts, or instructions to override agent safety guidelines were detected in the skill instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from git diffs and existing pull request content to generate its output. While this represents a data ingestion surface, the skill is designed for documentation and does not utilize sensitive data in a way that suggests a high risk of exploitable injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:18 AM
Security Audit — agent-trust-hub — writing-prs-and-commits