sync-docs
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of project source code and markdown documentation files.\n
- Ingestion points: Project files identified through
git ls-filesandglobpatterns inSKILL.md.\n - Boundary markers: The skill uses structured JSON output markers (
=== SYNC_DOCS_RESULT ===), but does not employ specific delimiters or 'ignore' instructions when reading individual file contents into the agent's context.\n - Capability inventory: The skill uses
gitcommands viaBash, reads file contents, and provides fix suggestions based on analysis.\n - Sanitization: While the implementation includes regex-based validation for git branch names (
/^[a-zA-Z0-9._-]+$/), it does not sanitize the contents of the documentation or code files being analyzed for potential embedded instructions.
Audit Metadata