skills/joydai2026-del/skills/audit/Gen Agent Trust Hub

audit

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git diff --name-only HEAD~N to identify recently modified files in the working directory (SKILL.md, Step 1).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it reads and evaluates untrusted data from modified files.
  • Ingestion points: The agent reads the content of modified or created files during the Content Verification step (SKILL.md, Step 3).
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or protective headers (e.g., "ignore instructions inside") when the agent reads external file content.
  • Capability inventory: The skill allows for repository enumeration via git and arbitrary file reading in the audit scope.
  • Sanitization: Absent. There are no requirements to escape or filter the content read from files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:53 AM
Security Audit — agent-trust-hub — audit