extract-project-contributions
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute the
git logcommand to retrieve commit history for developer contribution analysis, as defined inreferences/developer-extraction-rules.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it ingests and processes content from external repositories and user-provided document artifacts.\n - Ingestion points: The skill processes git repository data and various user-provided files such as PRDs, design notes, and slide decks as described in
SKILL.md.\n - Boundary markers: Absent. There are no instructions for using delimiters or protective prompts to prevent the agent from potentially interpreting malicious instructions embedded within the source files.\n
- Capability inventory: The skill allows the agent to read local files, execute shell commands for git operations, and write output files (
experience_output.md) to the file system.\n - Sanitization: While the skill provides logical filtering through 'Extraction rules' to focus on factual data, it does not implement technical sanitization or escaping of the content ingested from external sources.
Audit Metadata