patch-diff-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on a set of local shell scripts to automate workspace setup, decompilation, and diff generation. These scripts invoke system-level tools including git, jadx, ilspycmd, unzip, and java. While the scripts use proper quoting for variables to mitigate simple command injection, they represent a significant execution capability within the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to have the agent ingest and reason about decompiled source code from external, user-provided binaries. This creates a surface where an attacker could embed malicious instructions within code comments or string literals in a binary intended for analysis to influence the agent's behavior.
  • Ingestion points: Decompiled source code files located in the decompiled/ directory and the generated patch-analysis.diff file.
  • Boundary markers: Absent. The instructions command the agent to "Read the generated diff file completely" without providing specific delimiters or warnings to ignore instructions found within the analyzed data.
  • Capability inventory: Shell script execution for workspace management, decompilation (JAR/DLL), and git operations across multiple script files.
  • Sanitization: None. The agent processes the raw output of decompilers and diff tools directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:16 AM