code-review
Warn
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands (
git rev-parse,git diff,git log) using a user-provided 'fixed-point' value. This poses a command injection risk if the input contains shell metacharacters and is not correctly escaped by the agent platform. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted repository content. Ingestion points include git diff output, commit logs, and documentation/specification files from the repository. No specific boundary markers or encapsulation techniques are mentioned to separate untrusted data from the sub-agent instructions. The skill utilizes shell-based git tools and creates new sub-agent contexts to process analysis results. The instructions lack any requirement for sanitizing the repository-sourced data before its inclusion in prompts.
Audit Metadata