production-audit

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows security best practices by explicitly preventing the upload of repository content to third-party services and banning the use of unpinned remote scanners.
  • [COMMAND_EXECUTION]: Instructs the agent to run local, non-malicious version control commands such as git status, git log, and git diff to establish the release surface.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from repository file structure s, git history, and code contents. 1. Ingestion points: git log, git diff, Package script s, CI workflow s, Docker file s, and source code file s listed in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Local read-only git command s and file inspection; potential browser/HTTP check s agains t user-supplied url s. 4. Sanitization: No explicit sanitization of ingested content. This is a low-severity risk factor inherent to auditing and is mitigated by the lack of unsafe write or execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — production-audit