bump-submodules

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local build and test scripts (referred to as "the gate") to verify the stability of submodule updates. This is a standard and necessary function for a developer-oriented skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests untrusted data from submodule commit logs and user-provided reasons, which are then processed and included in Pull Request and Issue descriptions. Additionally, the build/test scripts it executes could potentially be influenced by code changes in the updated submodules.
  • Ingestion points: Submodule commit logs (git log), GitHub issue content (gh issue view), and direct human input (reason for the bump).
  • Boundary markers: The skill requires an explicit human-in-the-loop (HITL) confirmation of a "PLAN" before any changes are committed or issues are created.
  • Capability inventory: The skill possesses the ability to perform file writes, execute Git and GitHub CLI commands, and run arbitrary project-defined build/test scripts.
  • Sanitization: Data from external logs and user input is held verbatim for inclusion in documentation (Issues/PRs). No specific sanitization or filtering is mentioned, but the human review step serves as a primary control.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:00 AM
Security Audit — agent-trust-hub — bump-submodules