repo-state-diagnosis

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's operational contract strictly limits it to read-only Git inspection commands. It explicitly forbids commands that modify the index, working tree, or remote state, preventing accidental or malicious mutation.
  • [SAFE]: Comprehensive instructions are provided to identify and redact secret-like values during diagnosis. The skill includes a dedicated routing path to a 'secret-scan' skill when sensitive patterns are detected in diffs or files.
  • [SAFE]: The skill implements a 'no-evidence rule' which prevents the agent from making claims without observed command output, reducing the risk of hallucinations or misinformed actions in high-risk repository states.
  • [SAFE]: No external network dependencies, remote code execution patterns, or obfuscation techniques were found. The skill operates entirely within the local repository context using standard Git tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:19 AM
Security Audit — agent-trust-hub — repo-state-diagnosis