repo-status

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard Bash commands using git and gh tools to retrieve repository information. This behavior is consistent with the skill's description.
  • [PROMPT_INJECTION]: The skill processes external data, such as pull request titles and branch names retrieved from GitHub. While this constitutes an indirect prompt injection surface, the data is used solely to generate a textual summary for the user, which is the primary and expected function of the tool. There are no attempts to bypass safety filters or override agent behavior.
  • [DATA_EXFILTRATION]: The skill reads repository remote URLs and pull request metadata. This information is processed locally to generate a report and is not transmitted to unauthorized external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 12:00 PM