find-bugs
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes code content from a Git repository using
git diffand direct file reading without sanitizing the input or using clear boundary markers to isolate instructions. Malicious instructions embedded in the audited code (e.g., in comments or strings) could influence the agent's behavior. \n - Ingestion points: Untrusted data is ingested via Git CLI output and file system reads in Phase 1 and Phase 3. \n
- Boundary markers: The prompt does not utilize delimiters or specific instructions to ignore embedded commands within the ingested code. \n
- Capability inventory: The agent can read files and execute Git and GitHub CLI tools. \n
- Sanitization: There is no evidence of sanitization or filtering of the code content before it is passed to the LLM.
Audit Metadata