project-sync

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands including git, find, and ls to identify project structures, locate experimental results, and commit updates to the paper repository. These operations are restricted to the local filesystem and are necessary for the skill's primary synchronization purpose.\n- [PROMPT_INJECTION]: The skill ingests data from local files and user-provided input, which is then interpolated into LaTeX files and Git commit messages. While this creates a surface for indirect prompt injection (Category 8), the risk is minimal as the skill is designed for local productivity and includes manual confirmation steps before making changes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 12:40 PM
Security Audit — agent-trust-hub — project-sync