linux-repo-sync
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a bash function (
update_repo_safely) and references a script (sk-update-all-repos) that execute standard Git operations such asgit status,git pull,git rev-parse, andgit log. These commands are used for their intended purpose of repository management and follow safe practices by avoiding destructive flags. - [INDIRECT_PROMPT_INJECTION]: The skill defines a capability surface where external inputs (repository paths and branches) are ingested by the agent to perform actions.
- Ingestion points: Repository paths and branch names provided by the operator or a registry (referenced in
SKILL.md). - Boundary markers: The instructions do not specify explicit delimiters for path strings, but rely on standard shell variable handling.
- Capability inventory: The skill uses
cdandgitcommands to interact with the filesystem and remote repositories (referenced inSKILL.md). - Sanitization: The provided bash snippet does not show explicit path sanitization, but the doctrine requires manual operator intervention on conflicts and confirmation of repository paths, which acts as a human-in-the-loop control.
Audit Metadata