promote

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands such as git diff, ls, and make eval-all to extract repository statistics and performance metrics. It also calls the codesnap CLI tool to render images from text files.
  • [REMOTE_CODE_EXECUTION]: The skill instructions and reference materials require the agent to execute a Python script provided in references/templates.md to calculate the visual width of Unicode characters in generated tables, which constitutes dynamic execution of embedded code.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection by processing data from project files while maintaining execution capabilities. 1. Ingestion points: Reads data from CHANGELOG.md and CLAUDE.md. 2. Boundary markers: No delimiters or isolation markers are defined for the ingested data. 3. Capability inventory: Access to shell execution (git, make, codesnap) and Python interpretation. 4. Sanitization: No sanitization or validation of the ingested content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 12:42 PM