sync-provider

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions utilize coercive language patterns, specifically "TASK INVALIDATION" and "THE TASK WILL BE INVALIDATED," to force the agent into a specific sequence of operations. This is a common tactic to hijack the agent's internal priority and safety reasoning.
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection:
  • Ingestion points: Untrusted source code and git diffs are fetched from external repositories (e.g., github.com/ben-vargas/*) via the gh CLI and the scripts/git-diff.ts script.
  • Boundary markers: Absent. There are no instructions to use delimiters or ignore potential commands within the external data being analyzed.
  • Capability inventory: The agent is authorized to write to the local filesystem and execute shell commands based on the recommendations generated from the external data.
  • Sanitization: Absent. External content is analyzed by an LLM tool (Pal MCP refactor) without validation, which could allow malicious instructions in the upstream code to influence the agent's behavior.
  • [COMMAND_EXECUTION]: The workflow requires the execution of multiple local scripts, including scripts/check-provider-commit.sh and scripts/git-diff.ts, as well as standard CLI utilities like gh, pnpm, sed, grep, and cat to perform its syncing tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — sync-provider