aiagent-material-sync

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by explicitly prohibiting destructive git commands such as git reset --hard, git clean -fd, and force pushing in its safety section.
  • [SAFE]: The workflow is confined to standard, non-destructive git operations for synchronizing with an upstream repository, requiring user interaction for conflict resolution.
  • [PROMPT_INJECTION]: A potential surface for indirect prompt injection exists because the skill processes external data from the local repository state.
  • Ingestion points: The skill reads and evaluates output from git status and git remote -v to determine the synchronization path (SKILL.md).
  • Boundary markers: There are no explicit markers or instructions to ignore potential commands embedded in repository metadata.
  • Capability inventory: The skill has the authority to execute git fetch and git merge based on the ingested data (SKILL.md).
  • Sanitization: No specific validation or sanitization of branch names or remote URLs is described prior to command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — aiagent-material-sync