security-maintenance
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because its core function involves reading and interpreting untrusted repository data such as documentation, security policies, and contribution guides. This risk is inherent to the auditing use case.
- Ingestion points:
SKILL.md(Repository Contract Setup section, steps 1-5). - Boundary markers: The skill relies on human oversight and a formal contract process rather than data delimiters to isolate instructions.
- Capability inventory: File system modification, shell command execution (tests, linters, task runners), and git publication workflows.
- Sanitization: No explicit sanitization or filtering of codebase content is described.
- [COMMAND_EXECUTION]: The skill identifies and runs tools defined within the local repository (e.g., task runners, package scripts) to verify fixes. Executing code from an unfamiliar codebase is part of the intended functionality but is managed by requiring the user to explicitly approve the specific tooling and scope in the security contract before execution.
Audit Metadata