extract-project-contributions

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute the git log command to retrieve commit history for developer contribution analysis, as defined in references/developer-extraction-rules.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it ingests and processes content from external repositories and user-provided document artifacts.\n
  • Ingestion points: The skill processes git repository data and various user-provided files such as PRDs, design notes, and slide decks as described in SKILL.md.\n
  • Boundary markers: Absent. There are no instructions for using delimiters or protective prompts to prevent the agent from potentially interpreting malicious instructions embedded within the source files.\n
  • Capability inventory: The skill allows the agent to read local files, execute shell commands for git operations, and write output files (experience_output.md) to the file system.\n
  • Sanitization: While the skill provides logical filtering through 'Extraction rules' to focus on factual data, it does not implement technical sanitization or escaping of the content ingested from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:41 AM
Security Audit — agent-trust-hub — extract-project-contributions