undo-changes
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes Git CLI tools (including destructive commands like
git clean -f) to modify local repository state. It implements security best practices by instructing the agent to use--end-of-optionsand--delimiters to prevent malicious file names or paths from being interpreted as command arguments. - [PROMPT_INJECTION]: The skill processes untrusted repository metadata including commit messages, patches, mailbox bodies, and diffs, creating an indirect prompt injection surface. It explicitly addresses this by instructing the agent to treat repository-controlled text as data rather than authority and to ignore any instructions embedded within that data that attempt to expand scope or request credentials.
- Ingestion points: Repository files, commit messages, mailbox bodies, paths, refs, configuration, diffs, logs, and tool output (SKILL.md).
- Boundary markers: Explicit instructions to ignore embedded instructions and treat content as non-authoritative data.
- Capability inventory: Execution of shell-based Git commands (
git restore,git revert,git clean,git reset). - Sanitization: Use of
--end-of-optionsfor argument isolation and preview modes (git clean -n) before execution.
Audit Metadata