ubiquitous-language
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a custom Python script,
scripts/git_term_index.py, which executes localgitcommands via thesubprocessmodule. These calls are constructed as argument lists and do not invoke a shell, protecting against command injection. The operations are restricted to non-destructive analysis of local repository history.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external project data, such as thesaurus files and commit logs, which are potentially untrusted ingestion points.\n - Ingestion points: The agent reads the project's
THESAURUS.mdfile and uses a Python script to extract metadata fromgit logoutput.\n - Boundary markers: The skill specifies a rigid "grep-first" format for the thesaurus, using specific line patterns (Index, Terms, Forbidden, etc.) and tokens (
kind:,avoid:,ctx:) to structure how the agent interprets the data.\n - Capability inventory: The skill is permitted to use
Read,Write,Edit,Grep,Glob, andBashtools.\n - Sanitization: The instructions guide the agent to act only upon the structural "shape" of the data hits, providing a layer of validation against instructions embedded in prose or unrelated comments.
Audit Metadata