what-did-i-get-done
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes git commit history, which acts as a vector for untrusted data as commit messages may contain arbitrary text from various contributors.\n
- Ingestion points: Reads git commit messages by user email within a date range (SKILL.md).\n
- Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions that might be embedded within commit messages.\n
- Capability inventory: The skill performs reading of git history and text synthesis; it does not demonstrate network exfiltration, file system modification, or command execution capabilities.\n
- Sanitization: No sanitization or filtering of commit content is defined.
Audit Metadata