git-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and act upon data from external command outputs, creating a surface where instructions embedded in source code or command results could potentially influence agent actions. 1. Ingestion points: The agent reads output from git diff, forge test, and forge test --gas-report in SKILL.md. 2. Boundary markers: There are no explicit delimiters or instructions defined to isolate or ignore potentially malicious content within these outputs. 3. Capability inventory: The agent is authorized to perform git commit, git push, and git add operations. 4. Sanitization: The instructions do not specify any validation or sanitization procedures for the data ingested from command outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:53 AM
Security Audit — agent-trust-hub — git-workflow