skills/agent-sh/agentsys/repo-intel/Gen Agent Trust Hub

repo-intel

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external, potentially untrusted repository data such as git history and AST symbols, which provides a surface for indirect prompt injection attacks.
  • Ingestion points: Processes git history, AST symbols, and project metadata as defined in the description and Primary Responsibilities in SKILL.md.
  • Boundary markers: No delimiters or "ignore embedded instructions" warnings are specified for the ingested repository data.
  • Capability inventory: The skill triggers commands like /repo-intel and interacts with the map-validator agent to process the findings.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the external repository content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:14 AM
Security Audit — agent-trust-hub — repo-intel