contribute-adapter
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands for project synchronization, testing, and building, specifically:
uv sync,uv run pytest,just test-python,just lock-python,just wheels,just schemas,cargo fmt, andpre-commit. - [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent modifies repository code, package configurations, and metadata, followed by executing these modifications through test harnesses. This creates a potential vulnerability surface where malicious code or instructions embedded in the modified files could be executed by the agent during the validation process.
- Ingestion points: Files modified include Python and TypeScript adapter source code,
pyproject.toml,justfile, and adapter descriptor JSON files. - Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from obeying embedded logic within the modified files during testing.
- Capability inventory: Subprocess execution for testing and building using
uv,pytest,cargo, andjustcommands. - Sanitization: The skill relies on standard linting and formatting tools but lacks specific safeguards against execution of untrusted logic generated during the modification phase.
Audit Metadata