external-pr-style
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions and a reference list aimed at improving the tone of pull request descriptions. It does not contain any executable scripts, binary files, or dangerous system commands.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for transforming external data, such as code diffs and issue reports, into human-readable text. While this represents an ingestion surface for untrusted data, the skill is limited to stylistic filtering and does not include high-risk capabilities like network operations or code execution that could be exploited via injection.
- [EXTERNAL_DOWNLOADS]: The documentation references a specific GitHub repository (mattpocock/skills) as a source for text compression techniques. This is a static reference link to a well-known developer resource and does not trigger automated downloads or remote code execution.
Audit Metadata