repo-intel
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external, potentially untrusted repository data such as git history and AST symbols, which provides a surface for indirect prompt injection attacks.
- Ingestion points: Processes git history, AST symbols, and project metadata as defined in the description and Primary Responsibilities in
SKILL.md. - Boundary markers: No delimiters or "ignore embedded instructions" warnings are specified for the ingested repository data.
- Capability inventory: The skill triggers commands like
/repo-inteland interacts with themap-validatoragent to process the findings. - Sanitization: There is no evidence of sanitization, validation, or filtering of the external repository content before it is processed by the agent.
Audit Metadata