review-branch
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Git commands for repository analysis. It includes proactive security measures such as instructions to use
--end-of-optionsand--delimiters to prevent argument injection from untrusted branch names or file paths. It also specifies disabling optional locks and external diff tools to maintain a secure, read-only environment. - [DATA_EXFILTRATION]: The skill is restricted to read-only operations and authorized status queries. It explicitly routes secret-specific scanning to dedicated tools (
scan-secrets) and prohibits state-changing actions like pushing, publishing, or merging that could be used for exfiltration. - [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of processing untrusted repository data (commits, issue text, PR descriptions). It implements a secure workflow by instructing the agent to treat these as untrusted, resolve all references to immutable full OIDs (hashes), and prioritize material evidence over natural language claims in the analyzed data.
- Ingestion points: Branch names, revisions, file paths, repository text, issue content, and PR descriptions are identified as untrusted data sources in
SKILL.md. - Boundary markers: The skill mandates the use of
--for literal pathspec handling and--end-of-optionsto delimit untrusted input from command flags. - Capability inventory: Limited to local read-only Git inspections (e.g.,
git range-diff, history shape analysis) and authorized status queries. All mutation capabilities (checkout, commit, push, etc.) are strictly prohibited. - Sanitization: Arguments are sanitized by resolving potentially malicious ref names into exact OIDs and using standard Git safety flags.
Audit Metadata