uipath-source-control-conflicts

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and executes source-control commands (git merge/rebase) and project validation tools (builds, tests). Evidence: SKILL.md Workflow Steps 1, 5, and 6.\n- [DATA_EXFILTRATION]: The skill transmits project data to remote repositories via git operations. This is restricted to the user's authority and policy. Evidence: SKILL.md Workflow Step 6.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted data from commit messages, issues, and project files.\n
  • Ingestion points: commit messages, issues, SDD sections, tests, ADRs (SKILL.md, Step 2).\n
  • Boundary markers: Absent.\n
  • Capability inventory: File modification and command execution (SKILL.md, Steps 4, 5, 6).\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:39 PM
Security Audit — agent-trust-hub — uipath-source-control-conflicts