skills/agent-sh/agentsys/sync-docs/Gen Agent Trust Hub

sync-docs

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of project source code and markdown documentation files.\n
  • Ingestion points: Project files identified through git ls-files and glob patterns in SKILL.md.\n
  • Boundary markers: The skill uses structured JSON output markers (=== SYNC_DOCS_RESULT ===), but does not employ specific delimiters or 'ignore' instructions when reading individual file contents into the agent's context.\n
  • Capability inventory: The skill uses git commands via Bash, reads file contents, and provides fix suggestions based on analysis.\n
  • Sanitization: While the implementation includes regex-based validation for git branch names (/^[a-zA-Z0-9._-]+$/), it does not sanitize the contents of the documentation or code files being analyzed for potential embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:15 AM
Security Audit — agent-trust-hub — sync-docs