git-docs

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to search for and ingest content from external websites, specifically official Git documentation, to provide accurate answers. This creates a surface for indirect prompt injection if the ingested content were to contain malicious instructions.
  • Ingestion points: The agent is directed to fetch and read content from git-scm.com/docs/ and git-scm.com/book/en/v2 based on user queries.
  • Boundary markers: The instructions lack explicit boundary markers or "ignore" directives for the content fetched from the web.
  • Capability inventory: The skill is primarily informational and does not include scripts for file-system modification or command execution, limiting the impact of any potential injection.
  • Sanitization: There are no explicit instructions for the agent to sanitize or filter the content retrieved from the external documentation sources before processing it.
  • [SAFE]: The skill uses well-known and authoritative sources for Git documentation. Fetches and references to git-scm.com are for informational purposes and target the official repository of Git manuals and books, which is a standard and expected practice for a documentation-focused skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 11:51 AM
Security Audit — agent-trust-hub — git-docs