non-interactive-git-rebase
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- Command Execution through Git Interface: The skill utilizes the
GIT_SEQUENCE_EDITORenvironment variable and the--execflag to automate Git operations. These methods involve the execution of shell strings, which is a standard feature of Git but requires that the scripts be reviewed for robustness against unexpected input. - Dynamic Execution via Sequence Editor: The skill demonstrates how to dynamically generate Git todo files and have the Git process execute them. This pattern of runtime script generation is fundamental to the skill's purpose but is a form of dynamic execution.
- Processing of External Repository Data: The skill provides examples that extract and process metadata from the Git log, such as commit messages and author details. Since this data originates from the repository history, which could include contributions from various sources, it represents a potential surface for indirect prompt injection if malicious content is present in the history.
- Mandatory Security Assessment for Indirect Injection:
- Ingestion points: Repository metadata including commit messages, hashes, and author information extracted via
git logandgit rev-listinSKILL.md. - Boundary markers: The current implementation does not utilize explicit delimiters or warnings to isolate processed repository data.
- Capability inventory: The skill leverages shell command execution through the
GIT_SEQUENCE_EDITOR, the--execflag, and utility commands likesed,printf, andgit commitas seen inSKILL.md. - Sanitization: There is no evidence of specific sanitization or validation logic for the metadata before it is interpolated into shell commands.
- Shared Temporary Directory Usage: The skill uses
/tmp/for storing intermediate files like rebase todos and patches. While convenient, using shared temporary space on multi-user systems is a consideration when handling potentially sensitive repository content.
Audit Metadata