production-audit
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows security best practices by explicitly preventing the upload of repository content to third-party services and banning the use of unpinned remote scanners.
- [COMMAND_EXECUTION]: Instructs the agent to run local, non-malicious version control commands such as
git status,git log, andgit diffto establish the release surface. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from repository file structure s, git history, and code contents. 1. Ingestion points:
git log,git diff, Package script s, CI workflow s, Docker file s, and source code file s listed in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Local read-only git command s and file inspection; potential browser/HTTP check s agains t user-supplied url s. 4. Sanitization: No explicit sanitization of ingested content. This is a low-severity risk factor inherent to auditing and is mitigated by the lack of unsafe write or execution capabilities.
Audit Metadata