client-report-from-commits

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process git history (commit subjects, bodies, and diffs), which are external data sources that can be manipulated by anyone with commit access to the repository. An attacker could embed instructions in commit messages to deceive the agent during the summarization process.\n
  • Ingestion points: Git commit data is collected via scripts/collect_git_changes.py and potentially inspected using git show as per SKILL.md and references/workflow.md.\n
  • Boundary markers: The instructions do not define clear delimiters or provide 'ignore instructions' warnings for the data being analyzed.\n
  • Capability inventory: The skill possesses the ability to execute git commands, run internal Python scripts, and access the local file system within the git repository scope.\n
  • Sanitization: No sanitization, filtering, or validation of the commit message content is performed before the agent processes it.\n- [COMMAND_EXECUTION]: The skill requires the execution of shell commands and local scripts to perform its task.\n
  • Evidence: SKILL.md and references/workflow.md explicitly instruct the agent to run git rev-parse, git show, and python3 scripts/collect_git_changes.py.\n
  • Context: While these commands are standard for git analysis, they represent a capability surface that should be monitored for unexpected parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — client-report-from-commits