revert-change-safely
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Git logs, PR titles, and branch names to automate revert tasks and generate documentation. This creates a surface for indirect prompt injection where malicious instructions embedded in Git history could influence the agent's actions. * Ingestion points: Git commit messages via
git log, PR details viagh pr view, and branch names identified inSKILL.md. * Boundary markers: Absent; there are no instructions for the agent to distinguish between data and potential instructions within the fetched strings. * Capability inventory: Write access to the repository viagit revertandgit push, and interaction with GitHub viagh pr createas seen inSKILL.md. * Sanitization: The skill lacks mechanisms to sanitize or escape user-controlled text before it is interpolated into new commit messages or PR descriptions. - [PROMPT_INJECTION]: The instructions explicitly command the agent to strip all 'agentic annotations' and AI attribution markers (such as 'Generated with...' or robot emojis) from commit messages and PRs. This is a concealment technique that prevents users from identifying AI-generated contributions to the codebase.
- [COMMAND_EXECUTION]: The skill performs shell command execution using
git,gh, andnpmto manage the repository and verify the build. These capabilities are necessary for the skill's purpose but represent a high-privilege tier that processes the aforementioned untrusted data.
Audit Metadata