summarize-changes
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data (code changes, file contents) which presents a surface for indirect prompt injection.
- Ingestion points: The skill instructions in
SKILL.mddirect the agent to gather information from modified files andgitcommand output. - Boundary markers: The instructions lack explicit boundary markers or warnings to the agent to ignore potentially malicious instructions embedded within the code comments or content being summarized.
- Capability inventory: The skill utilize
Read,Glob,Grep, andBashtools to analyze project files. - Sanitization: There is no evidence of data sanitization or validation of the ingested file content before it is processed by the model for summarization.
Audit Metadata