client-report-from-commits
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process git history (commit subjects, bodies, and diffs), which are external data sources that can be manipulated by anyone with commit access to the repository. An attacker could embed instructions in commit messages to deceive the agent during the summarization process.\n
- Ingestion points: Git commit data is collected via
scripts/collect_git_changes.pyand potentially inspected usinggit showas perSKILL.mdandreferences/workflow.md.\n - Boundary markers: The instructions do not define clear delimiters or provide 'ignore instructions' warnings for the data being analyzed.\n
- Capability inventory: The skill possesses the ability to execute git commands, run internal Python scripts, and access the local file system within the git repository scope.\n
- Sanitization: No sanitization, filtering, or validation of the commit message content is performed before the agent processes it.\n- [COMMAND_EXECUTION]: The skill requires the execution of shell commands and local scripts to perform its task.\n
- Evidence:
SKILL.mdandreferences/workflow.mdexplicitly instruct the agent to rungit rev-parse,git show, andpython3 scripts/collect_git_changes.py.\n - Context: While these commands are standard for git analysis, they represent a capability surface that should be monitored for unexpected parameters.
Audit Metadata