git-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suggests installing git-filter-repo via pip as a recommended alternative to git filter-branch. This is a standard and highly regarded community tool for repository maintenance and history rewriting.
  • [COMMAND_EXECUTION]: The instructions utilize complex shell pipelines involving grep and xargs (e.g., git branch --merged | grep -v "\*" | xargs -n 1 git branch -d) to automate repository cleanup tasks like removing merged branches. It also includes an automated bug-finding workflow using git bisect run ./test.sh, which executes a local script.
  • [INDIRECT_PROMPT_INJECTION]:
    • Ingestion points: The agent reads untrusted data from the local repository environment using commands like git log, git show, git diff, and git status, which display commit messages, author metadata, and file contents.
    • Boundary markers: The instructions do not define explicit boundary markers or provide "ignore embedded instructions" warnings for the agent when processing git output.
    • Capability inventory: The agent is granted capabilities to modify the local file system (Write, Edit) and execute shell commands (Bash(git:*)).
    • Sanitization: There is no evidence of sanitization, escaping, or validation applied to the data retrieved from the Git history before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:42 PM
Security Audit — agent-trust-hub — git-expert