patch-diff-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on a set of local shell scripts to automate workspace setup, decompilation, and diff generation. These scripts invoke system-level tools including
git,jadx,ilspycmd,unzip, andjava. While the scripts use proper quoting for variables to mitigate simple command injection, they represent a significant execution capability within the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to have the agent ingest and reason about decompiled source code from external, user-provided binaries. This creates a surface where an attacker could embed malicious instructions within code comments or string literals in a binary intended for analysis to influence the agent's behavior.
- Ingestion points: Decompiled source code files located in the
decompiled/directory and the generatedpatch-analysis.difffile. - Boundary markers: Absent. The instructions command the agent to "Read the generated diff file completely" without providing specific delimiters or warnings to ignore instructions found within the analyzed data.
- Capability inventory: Shell script execution for workspace management, decompilation (JAR/DLL), and git operations across multiple script files.
- Sanitization: None. The agent processes the raw output of decompilers and diff tools directly.
Audit Metadata