non-interactive-git-rebase

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • Command Execution through Git Interface: The skill utilizes the GIT_SEQUENCE_EDITOR environment variable and the --exec flag to automate Git operations. These methods involve the execution of shell strings, which is a standard feature of Git but requires that the scripts be reviewed for robustness against unexpected input.
  • Dynamic Execution via Sequence Editor: The skill demonstrates how to dynamically generate Git todo files and have the Git process execute them. This pattern of runtime script generation is fundamental to the skill's purpose but is a form of dynamic execution.
  • Processing of External Repository Data: The skill provides examples that extract and process metadata from the Git log, such as commit messages and author details. Since this data originates from the repository history, which could include contributions from various sources, it represents a potential surface for indirect prompt injection if malicious content is present in the history.
  • Mandatory Security Assessment for Indirect Injection:
  • Ingestion points: Repository metadata including commit messages, hashes, and author information extracted via git log and git rev-list in SKILL.md.
  • Boundary markers: The current implementation does not utilize explicit delimiters or warnings to isolate processed repository data.
  • Capability inventory: The skill leverages shell command execution through the GIT_SEQUENCE_EDITOR, the --exec flag, and utility commands like sed, printf, and git commit as seen in SKILL.md.
  • Sanitization: There is no evidence of specific sanitization or validation logic for the metadata before it is interpolated into shell commands.
  • Shared Temporary Directory Usage: The skill uses /tmp/ for storing intermediate files like rebase todos and patches. While convenient, using shared temporary space on multi-user systems is a consideration when handling potentially sensitive repository content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:01 AM