investigating-repository-history
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Python
subprocessmodule to executegitandgh(GitHub CLI) commands for repository analysis. It retrieves information through standard operations such asblame,log, andgh apicalls, which are necessary for its documented functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by fetching GitHub Pull Request bodies, review comments, and commit messages. This data is provided to the agent as evidence, creating a potential surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context via
gh apicalls inscripts/history_context.pyandscripts/compact_pr.py. - Boundary markers:
SKILL.mdprovides instructions for assessing evidence confidence but does not utilize specific delimiters to isolate the untrusted external text. - Capability inventory: The skill scripts possess capabilities to execute shell commands and read/write files within the repository scope.
- Sanitization: The scripts implement basic formatting and length truncation for retrieved text but do not include specific sanitization aimed at preventing instruction injection.
- [EXTERNAL_DOWNLOADS]: The skill downloads repository metadata and history from GitHub via the authenticated
ghCLI. These operations are legitimate and scoped to the repository being investigated.
Audit Metadata