nightly-sync

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git, gh (GitHub CLI), and docker to perform synchronization and CI monitoring tasks. These tools are used to manage the repository and interact with the development environment.
  • [EXTERNAL_DOWNLOADS]: The skill performs pip install uv==0.7.2 and pulls a specific Docker image nvcr.io/nvidia/pytorch:26.02-py3 from NVIDIA's container registry. These resources are owned by the vendor and are necessary for the synchronization workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data including git diffs, commit logs, and CI job logs to identify failures and resolve conflicts.
  • Ingestion points: SKILL.md defines workflows that ingest git history and CI logs.
  • Boundary markers: No specific boundary markers are defined for this external content.
  • Capability inventory: The agent has access to git, gh, docker, and Python formatting tools (black, isort, pylint).
  • Sanitization: No explicit sanitization or filtering is applied to the ingested logs or code before processing.
  • [DYNAMIC_EXECUTION]: The skill provides bash templates for the agent to execute for pre-push checks and CI monitoring. These templates are documented as part of the core workflow and do not involve executing untrusted or dynamically assembled code outside of the controlled environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:20 PM
Security Audit — agent-trust-hub — nightly-sync