git-docs
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to search for and ingest content from external websites, specifically official Git documentation, to provide accurate answers. This creates a surface for indirect prompt injection if the ingested content were to contain malicious instructions.
- Ingestion points: The agent is directed to fetch and read content from
git-scm.com/docs/andgit-scm.com/book/en/v2based on user queries. - Boundary markers: The instructions lack explicit boundary markers or "ignore" directives for the content fetched from the web.
- Capability inventory: The skill is primarily informational and does not include scripts for file-system modification or command execution, limiting the impact of any potential injection.
- Sanitization: There are no explicit instructions for the agent to sanitize or filter the content retrieved from the external documentation sources before processing it.
- [SAFE]: The skill uses well-known and authoritative sources for Git documentation. Fetches and references to
git-scm.comare for informational purposes and target the official repository of Git manuals and books, which is a standard and expected practice for a documentation-focused skill.
Audit Metadata