dotnet-mcaf-source-control
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill focuses on documentation and policy guidance for source control. It explicitly treats secrets in git as critical incidents requiring rotation and history cleaning, which aligns with security best practices.
- [NO_CODE]: The skill does not include any executable scripts, binaries, or automated command execution. It relies entirely on natural language instructions and reference documentation.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes repository files to update documentation.
- Ingestion points: Reads repository content including 'AGENTS.md' and repository policy files (SKILL.md).
- Boundary markers: No explicit delimiters or instructions are used to separate untrusted repository content from the agent's system instructions.
- Capability inventory: The skill can modify repository documentation, contribution guidelines, and governance files (SKILL.md).
- Sanitization: No sanitization or validation of input file content is performed before processing.
Audit Metadata