commit-message
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses
gh(GitHub CLI) to read public pull request information such as titles, bodies, and comments, which is standard for developer tooling. - [SAFE]: The skill performs username resolution by checking redirects on
profiles.wordpress.org. This is a legitimate way to map GitHub usernames to WordPress.org IDs for attribution in commit messages. - [SAFE]: The skill integrates with a WordPress Trac MCP server to fetch ticket details and discussion. This is a scoped, read-only operation used to gather context for the commit message.
- [SAFE]: The skill instructions specify outputting only the formatted commit message and explicitly warn against including unverified usernames in the final output.
- [SAFE]: No suspicious patterns, obfuscation, or unauthorized data exfiltration were detected. All external network operations (GitHub CLI and WordPress.org lookups) are directly related to the skill's stated purpose.
Audit Metadata