simplify
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes git commands (e.g., git diff @{upstream}...HEAD) using arguments provided by the user, such as PR numbers or branch names. This introduces a risk of command injection if the execution environment does not properly sanitize these inputs.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it reads and processes untrusted code diffs, which are then passed to subordinate cleanup agents. 1. Ingestion points: Code diffs retrieved via git commands (SKILL.md). 2. Boundary markers: There are no explicit delimiters or instructions for agents to ignore instructions within the code content. 3. Capability inventory: The skill can launch agents and apply file modifications based on findings. 4. Sanitization: No sanitization of the code content is performed.
Audit Metadata