lesson-learned

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted commit messages and code diffs which may contain adversarial instructions. 1. Ingestion points: git log and git diff outputs (SKILL.md). 2. Boundary markers: Absent; no delimiters are used to wrap external content. 3. Capability inventory: Read-only access to git repository history and file content via git CLI tools. 4. Sanitization: Absent; no validation of external content.
  • [COMMAND_EXECUTION]: The skill invokes local git commands such as git log, git show, and git diff to perform its primary function of code analysis. While restricted to git, these are shell-executed commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — lesson-learned