create-pr-commit
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWNO_CODE
Full Analysis
- [No Code] (SAFE): The skill consists entirely of natural language instructions and examples. There are no associated scripts (Python, JavaScript, Bash) or binaries, which eliminates risks related to remote code execution or malware.
- [Prompt Injection] (SAFE): The instructions are focused solely on formatting commit messages. There are no patterns suggesting attempts to bypass safety filters, extract system prompts, or override agent constraints.
- [Data Exposure] (SAFE): While the workflow involves reading repository files (like CONTRIBUTING.md) to understand naming conventions, there are no commands to access sensitive directories (e.g., .ssh, .aws) or exfiltrate data via network requests.
Audit Metadata