sync-provider

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes code diffs from external GitHub repositories and utilizes an LLM-based refactoring tool (Pal MCP) to analyze and plan the application of these changes. This creates an attack surface for indirect prompt injection where a malicious upstream repository could include instructions within comments or code designed to manipulate the agent during the synchronization workflow.
  • Ingestion points: Remote repository content is fetched and stored in the .diffs/ directory via the git-diff.ts script.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to ignore embedded commands within the ingested diff files.
  • Capability inventory: The agent has the authority to write files to the local providers/ directory and execute shell commands for testing (pnpm test) and linting.
  • Sanitization: No automated sanitization is performed on the incoming diff data before it is analyzed by the refactoring LLM.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell command substitution and pipes (using grep, sed, cut, and find) to extract metadata from package.json files and manage sync states. These commands interpolate variables derived from local file content, which could lead to unexpected execution patterns if those files are modified by untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — sync-provider