why
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard command-line tools such as
gitandghto extract version control history, line-level attribution, and pull request metadata. These operations are restricted to the local repository and the project's official GitHub environment. - [DATA_EXFILTRATION]: The skill aggregates data from internal sources (Slack, Notion, Datadog, Linear, Sentry, Databricks) using the Model Context Protocol (MCP). The purpose of this aggregation is to synthesize a 'why' report for the user. No evidence was found of data being transmitted to unauthorized external domains or third-party servers.
- [INDIRECT_PROMPT_INJECTION]: By ingesting data from external sources like PR comments, Slack threads, and issue descriptions, the skill has an exposure surface for indirect prompt injection. However, the skill incorporates an 'Epistemics Framework' and specific 'Operating Postures' that instruct the agent to prioritize verbatim citations and maintain high skepticism toward interpreted intent, which serves as a mitigation against such attacks.
- [REMOTE_CODE_EXECUTION]: The skill orchestrates sub-agents (using
composer-2.5-fastandclaude-opus-4-7-thinking-xhigh) to perform parallel investigations. This is a legitimate architectural pattern for complex analysis tasks and does not involve the execution of untrusted remote scripts.
Audit Metadata