revert-change-safely

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Git logs, PR titles, and branch names to automate revert tasks and generate documentation. This creates a surface for indirect prompt injection where malicious instructions embedded in Git history could influence the agent's actions. * Ingestion points: Git commit messages via git log, PR details via gh pr view, and branch names identified in SKILL.md. * Boundary markers: Absent; there are no instructions for the agent to distinguish between data and potential instructions within the fetched strings. * Capability inventory: Write access to the repository via git revert and git push, and interaction with GitHub via gh pr create as seen in SKILL.md. * Sanitization: The skill lacks mechanisms to sanitize or escape user-controlled text before it is interpolated into new commit messages or PR descriptions.
  • [PROMPT_INJECTION]: The instructions explicitly command the agent to strip all 'agentic annotations' and AI attribution markers (such as 'Generated with...' or robot emojis) from commit messages and PRs. This is a concealment technique that prevents users from identifying AI-generated contributions to the codebase.
  • [COMMAND_EXECUTION]: The skill performs shell command execution using git, gh, and npm to manage the repository and verify the build. These capabilities are necessary for the skill's purpose but represent a high-privilege tier that processes the aforementioned untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — revert-change-safely