bump-submodules
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local build and test scripts (referred to as "the gate") to verify the stability of submodule updates. This is a standard and necessary function for a developer-oriented skill.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests untrusted data from submodule commit logs and user-provided reasons, which are then processed and included in Pull Request and Issue descriptions. Additionally, the build/test scripts it executes could potentially be influenced by code changes in the updated submodules.
- Ingestion points: Submodule commit logs (
git log), GitHub issue content (gh issue view), and direct human input (reason for the bump). - Boundary markers: The skill requires an explicit human-in-the-loop (HITL) confirmation of a "PLAN" before any changes are committed or issues are created.
- Capability inventory: The skill possesses the ability to perform file writes, execute Git and GitHub CLI commands, and run arbitrary project-defined build/test scripts.
- Sanitization: Data from external logs and user input is held verbatim for inclusion in documentation (Issues/PRs). No specific sanitization or filtering is mentioned, but the human review step serves as a primary control.
Audit Metadata