discover-repository-state

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill does not contain hardcoded credentials, malicious obfuscation, persistence mechanisms, or unauthorized network activity. All behaviors described align with the stated goal of repository state documentation.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface due to its core function of reading untrusted repository data. Maliciously crafted content in the repository could attempt to subvert the discovery process.
  • Ingestion points: Repository files, tests, git state, and existing REPOSITORY_STATE.md ledgers.
  • Boundary markers: Present. The skill mandates strict separation into 'Repository Facts', 'Accepted Decisions', 'Planned work', 'Documentation', and 'Inference' sections to prevent data confusion.
  • Capability inventory: Subprocess execution for gathering evidence and repository file system access (SKILL.md).
  • Sanitization: Absent. The process relies on the structural isolation of different data types rather than content sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 05:30 PM
Security Audit — agent-trust-hub — discover-repository-state