merge-stack

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates within the scope of its intended functionality using the official GitHub CLI, which is a trusted service for this task.\n- [SAFE]: No hardcoded credentials, malicious remote downloads, or obfuscated code were detected.\n- [SAFE]: Security is maintained through a 'human-in-the-loop' approach, requiring the agent to present the merge plan to the user for confirmation before execution.\n- [SAFE]: The risk of indirect prompt injection from GitHub metadata (like PR titles) is mitigated by disabling model invocation during the execution of the merge workflow, ensuring the data is not interpreted as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 08:18 PM