pr-description
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from git repositories.
- Ingestion points: Git diffs, commit lists, and change summaries provided as input (described in
SKILL.md). - Boundary markers: Absent; there are no delimiters specified to separate user data from instructions.
- Capability inventory: None; the skill does not use tools, perform network operations, or execute code.
- Sanitization: Absent; the skill does not provide instructions for the agent to sanitize or escape input data.
- [NO_CODE]: The skill consists entirely of natural language instructions and does not contain any executable scripts, binary files, or external code dependencies.
Audit Metadata