commit-message

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses gh (GitHub CLI) to read public pull request information such as titles, bodies, and comments, which is standard for developer tooling.
  • [SAFE]: The skill performs username resolution by checking redirects on profiles.wordpress.org. This is a legitimate way to map GitHub usernames to WordPress.org IDs for attribution in commit messages.
  • [SAFE]: The skill integrates with a WordPress Trac MCP server to fetch ticket details and discussion. This is a scoped, read-only operation used to gather context for the commit message.
  • [SAFE]: The skill instructions specify outputting only the formatted commit message and explicitly warn against including unverified usernames in the final output.
  • [SAFE]: No suspicious patterns, obfuscation, or unauthorized data exfiltration were detected. All external network operations (GitHub CLI and WordPress.org lookups) are directly related to the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 09:00 PM
Security Audit — agent-trust-hub — commit-message