repoprompt
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the local
rp-cliutility and a feedback recording script (record_skill_feedback.py) as part of its standard workflow. - [DATA_EXFILTRATION]: Features an 'Oracle Export' mode that gathers repository context into a local file for external consultation, which is a documented and intended capability.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8). Ingestion points: Untrusted repository data is ingested via file-reading and search tools specified in
references/repoprompt_mcp_tooling.mdandreferences/repoprompt_cli_tooling.md. Boundary markers: The instructions do not specify boundary markers or instructions to ignore embedded prompts for ingested content. Capability inventory: The skill possesses file-modification capabilities through tools likeapply_editsandfile_actions. Sanitization: No sanitization or validation of ingested repository data is mentioned.
Audit Metadata