ponytail-debt
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Uses the
grepandgit blameshell commands to search for specific strings and identify file line authorship. These commands are executed locally for the purpose of generating a report and do not involve remote network access or privileged operations. - [SAFE]: Processes data from source code comments which serves as an ingestion point for untrusted content. While this creates a potential surface for indirect prompt injection, the skill's functionality is restricted to reporting and does not provide an execution path for instructions embedded within those comments.
Audit Metadata