weekly-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted commit messages and repository data which could contain malicious prompts designed to manipulate the agent's behavior during summary generation.
- Ingestion points: Ingests authored commits and diffs from the git repository context as described in the
SKILL.mdworkflow. - Boundary markers: Absent. There are no instructions or delimiters instructing the agent to ignore prompt instructions that may be embedded within commit messages.
- Capability inventory: The skill is restricted to read-only summary actions and contains no capabilities for network requests, file modifications, or process execution.
- Sanitization: No escaping or validation is performed on the ingested git commit data before processing.
Audit Metadata