sync-provider
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes code diffs from external GitHub repositories and utilizes an LLM-based refactoring tool (Pal MCP) to analyze and plan the application of these changes. This creates an attack surface for indirect prompt injection where a malicious upstream repository could include instructions within comments or code designed to manipulate the agent during the synchronization workflow.
- Ingestion points: Remote repository content is fetched and stored in the
.diffs/directory via thegit-diff.tsscript. - Boundary markers: The skill lacks explicit boundary markers or instructions to ignore embedded commands within the ingested diff files.
- Capability inventory: The agent has the authority to write files to the local
providers/directory and execute shell commands for testing (pnpm test) and linting. - Sanitization: No automated sanitization is performed on the incoming diff data before it is analyzed by the refactoring LLM.
- [COMMAND_EXECUTION]: The skill makes extensive use of shell command substitution and pipes (using
grep,sed,cut, andfind) to extract metadata frompackage.jsonfiles and manage sync states. These commands interpolate variables derived from local file content, which could lead to unexpected execution patterns if those files are modified by untrusted sources.
Audit Metadata