apollousa
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes metadata from the local Git environment which acts as a surface for indirect instructions from repository contents.- Ingestion points: Git repository state including branch names, status, and PR metadata.- Capabilities: Git commands, branch creation, PR submission, and tool invocation.- Boundary markers: The skill does not explicitly use delimiters to separate repository data from instructions.- Sanitization: The skill relies on standard agent behavior without additional sanitization layers.- [COMMAND_EXECUTION]: The skill executes validation commands based on the repository's specific requirements.- Evidence: The instruction to run the repository's required validation before pushing code results in the execution of local scripts.
Audit Metadata