ln-61-repository-publisher

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Native Git CLI, hosting CLI/API tools, and repository-native validation commands to manage repository state, staging, and synchronization.
  • [DYNAMIC_EXECUTION]: The skill executes repository-native validation scripts and performs clean-source verification, which may involve the installation and execution of code found within the target repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data such as repository instructions, release rules, and branch policies to guide its internal state tracking and decision-making.
  • Ingestion points: Reads repository-level configuration files and hosting policy descriptions (SKILL.md).
  • Boundary markers: The skill defines a checklist but lacks explicit delimiters to separate repository-provided instructions from its own execution logic.
  • Capability inventory: Full Git CLI access, hosting API communication, and shell command execution across multiple scripts (SKILL.md).
  • Sanitization: Includes safety gates to exclude secrets but does not specify filtering for natural language instructions in ingested files.
  • [PROMPT_INJECTION]: Contains instructions directing the agent not to "invent approval gates from caution" when encountering instructional blocks, which could be interpreted as a directive to override standard safety constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 07:50 AM
Security Audit — agent-trust-hub — ln-61-repository-publisher