contribute-adapter

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands for project synchronization, testing, and building, specifically: uv sync, uv run pytest, just test-python, just lock-python, just wheels, just schemas, cargo fmt, and pre-commit.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent modifies repository code, package configurations, and metadata, followed by executing these modifications through test harnesses. This creates a potential vulnerability surface where malicious code or instructions embedded in the modified files could be executed by the agent during the validation process.
  • Ingestion points: Files modified include Python and TypeScript adapter source code, pyproject.toml, justfile, and adapter descriptor JSON files.
  • Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from obeying embedded logic within the modified files during testing.
  • Capability inventory: Subprocess execution for testing and building using uv, pytest, cargo, and just commands.
  • Sanitization: The skill relies on standard linting and formatting tools but lacks specific safeguards against execution of untrusted logic generated during the modification phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 12:07 AM
Security Audit — agent-trust-hub — contribute-adapter