skills/delorenj/skills/recap/Gen Agent Trust Hub

recap

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill probes CLI capabilities by executing local repository commands with help flags in temporary worktrees to detect changes in behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted sources including git commit messages, repository content, and external ticket platforms (Jira, Linear). Ingestion points include git log bodies and ticket timelines. Capability inventory includes local command execution and file writes to the .recaps directory. The skill mitigates risks via strict rendering budgets, HTML escaping of commit and ticket titles, and a redaction allowlist.
  • [DATA_EXFILTRATION]: The skill may access external APIs to retrieve ticket history and monitors local configuration files like .env for changes. It enforces a redaction policy that only allows specific metadata to be quoted verbatim to prevent secret exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — recap