truthsync
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard command-line tools such as
git logandgrepto inspect the repository's version history and source code. These operations are restricted to the local repository context and are necessary for the skill's stated purpose of documentation synchronization. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from git commit messages and PR descriptions during its analysis phase. While this presents an inherent surface for indirect prompt injection, the risk is minimal as the skill's output is limited to proposing documentation updates in a new pull request, which undergoes human review before merging.
Audit Metadata