continue
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as
git log --oneline -10andgit statusto gather context about the current repository state, as well as checking live processes and worktrees. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources including git history, live process information, and ledger rows which may contain content from external contributors.
- Ingestion points: Reads output from
git log,git status,/tmpartifacts, live process lists, and ledger database rows (SKILL.md). - Boundary markers: None provided in the instructions to distinguish between the gathered evidence and the agent's internal instructions.
- Capability inventory: Execution of git commands, file system reads, process inspection, and interaction with a ledger system for task tracking.
- Sanitization: No explicit sanitization or validation of the input data is described before it is incorporated into the agent's state dump.
Audit Metadata