external-pr-style

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions and a reference list aimed at improving the tone of pull request descriptions. It does not contain any executable scripts, binary files, or dangerous system commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for transforming external data, such as code diffs and issue reports, into human-readable text. While this represents an ingestion surface for untrusted data, the skill is limited to stylistic filtering and does not include high-risk capabilities like network operations or code execution that could be exploited via injection.
  • [EXTERNAL_DOWNLOADS]: The documentation references a specific GitHub repository (mattpocock/skills) as a source for text compression techniques. This is a static reference link to a well-known developer resource and does not trigger automated downloads or remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 05:53 AM
Security Audit — agent-trust-hub — external-pr-style