lfg

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill autonomously executes CLI tools including git and the GitHub CLI (gh) to resolve repository paths, check remote status, commit changes, and push branches. These commands are dynamically constructed based on the workflow state.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data such as user requests, issue tickets, and stack traces, which are passed through multiple agentic stages.
  • Ingestion points: Entry points for untrusted data are identified in SKILL.md and references/intake.md, including feature descriptions and issue references.
  • Boundary markers: The skill implements a 'settled-decisions brief' to isolate user-approved decisions and sanitizes routing directives as specified in references/stage-routing.md.
  • Capability inventory: The skill has the capability to modify repository files, execute shell commands, and transmit data to remote servers.
  • Sanitization: Logical sanitization is performed to strip operational routing instructions from the prompts sent to planning and implementation sub-skills.
  • [DATA_EXFILTRATION]: By design, the skill pushes local repository changes to remote git servers and transmits diagnostic findings to external trackers such as Linear, Jira, or GitHub Issues. This involves the transfer of local project content to third-party services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:35 AM
Security Audit — agent-trust-hub — lfg