diff-preview
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interpolates untrusted data from git diffs directly into AI prompts without sanitization or boundary markers.
- Ingestion points: Git diff contents are captured in variables (such as
$DIFF) and embedded in prompt strings insideSKILL.md. - Boundary markers: Absent. The diff content is placed directly below the prompt text without clear delimiters or defensive instructions.
- Capability inventory: The skill utilizes local
gitCLI operations and invokes the externalgeminicommand-line tool. - Sanitization: Absent. No escaping, validation, or filtering is applied to the diff outputs before transmission to the model.
Audit Metadata