git-developer-performance
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
child_process.execFileSyncto execute standardgitcommands (e.g.,git log,git rev-parse,git show). Analysis shows these commands are safely constructed with an array of arguments, preventing shell injection. Input like branch names is validated against control characters and unsafe ref sequences (e.g.,..,@{,\\). - [DATA_EXPOSURE_&_EXFILTRATION]: The skill instructions explicitly mandate using local Git history only and forbid querying external services. All network-related tools are absent from the
allowed-toolsor script implementation. The script strictly processes local repository data. - [PRIVILEGE_ESCALATION]: The skill operates within the user's current environment and does not attempt to use
sudoor modify system-level configurations. It enforces that its output remains outside the.claudeconfiguration directory to prevent internal state pollution. - [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. All scripts are local to the skill package, and dependencies are limited to standard Node.js built-ins (
fs,path,crypto,child_process). - [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it reads
git logoutput and commit patches (viagit show). However, it includes specific instructions for the agent to treat these as evidence-based estimates and provides clear boundary markers in the generatedwork-packets/*.mdfiles. The risk is mitigated by the analytical nature of the task and the lack of high-privilege write capabilities for the ingested data.
Audit Metadata