repoprompt

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the local rp-cli utility and a feedback recording script (record_skill_feedback.py) as part of its standard workflow.
  • [DATA_EXFILTRATION]: Features an 'Oracle Export' mode that gathers repository context into a local file for external consultation, which is a documented and intended capability.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8). Ingestion points: Untrusted repository data is ingested via file-reading and search tools specified in references/repoprompt_mcp_tooling.md and references/repoprompt_cli_tooling.md. Boundary markers: The instructions do not specify boundary markers or instructions to ignore embedded prompts for ingested content. Capability inventory: The skill possesses file-modification capabilities through tools like apply_edits and file_actions. Sanitization: No sanitization or validation of ingested repository data is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:14 PM
Security Audit — agent-trust-hub — repoprompt