repoprompt
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the agent to use the
Bashtool to runrp-clicommands and execute asynchronous python workflows viauv runfor repository analysis. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it retrieves and processes content from external repositories that could contain malicious instructions.
- Ingestion points: Codebase files, search matches, and structural data read via the
rp-clitool as documented inSKILL.md. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are detailed within the skill guidelines.
- Capability inventory: The agent maintains the ability to execute shell commands using the
Bashtool to run local scripts and CLI tools. - Sanitization: Input sanitization or data verification mechanisms are absent within the text of the skill context.
Audit Metadata