production-audit

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill instructions emphasize secure auditing practices by explicitly prohibiting the use of unpinned remote code and the uploading of repository data to third-party services.
  • [COMMAND_EXECUTION]: The skill utilizes standard version control commands to analyze the repository state. Evidence includes commands like git status, git log, and git diff. These are standard auditing tools used within their intended scope.
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection because it processes content from the repository being audited. * Ingestion points: The agent reads local repository files (source code, configuration, manifests) and command outputs (git logs, diffs). * Boundary markers: None specified for separating system instructions from project data. * Capability inventory: Limited to read-only file access and standard git commands; the skill does not instruct the agent to execute untrusted code or write to the filesystem. * Sanitization: No specific sanitization or validation of repository content is mentioned. Given the primary purpose is auditing, this is a known surface managed by the skill's restricted capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:17 AM
Security Audit — agent-trust-hub — production-audit