project-sync
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands including
git,find, andlsto identify project structures, locate experimental results, and commit updates to the paper repository. These operations are restricted to the local filesystem and are necessary for the skill's primary synchronization purpose.\n- [PROMPT_INJECTION]: The skill ingests data from local files and user-provided input, which is then interpolated into LaTeX files and Git commit messages. While this creates a surface for indirect prompt injection (Category 8), the risk is minimal as the skill is designed for local productivity and includes manual confirmation steps before making changes.
Audit Metadata