sync-provider
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions utilize coercive language patterns, specifically "TASK INVALIDATION" and "THE TASK WILL BE INVALIDATED," to force the agent into a specific sequence of operations. This is a common tactic to hijack the agent's internal priority and safety reasoning.
- [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection:
- Ingestion points: Untrusted source code and git diffs are fetched from external repositories (e.g.,
github.com/ben-vargas/*) via theghCLI and thescripts/git-diff.tsscript. - Boundary markers: Absent. There are no instructions to use delimiters or ignore potential commands within the external data being analyzed.
- Capability inventory: The agent is authorized to write to the local filesystem and execute shell commands based on the recommendations generated from the external data.
- Sanitization: Absent. External content is analyzed by an LLM tool (Pal MCP refactor) without validation, which could allow malicious instructions in the upstream code to influence the agent's behavior.
- [COMMAND_EXECUTION]: The workflow requires the execution of multiple local scripts, including
scripts/check-provider-commit.shandscripts/git-diff.ts, as well as standard CLI utilities likegh,pnpm,sed,grep, andcatto perform its syncing tasks.
Audit Metadata