linux-repo-sync

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a bash function (update_repo_safely) and references a script (sk-update-all-repos) that execute standard Git operations such as git status, git pull, git rev-parse, and git log. These commands are used for their intended purpose of repository management and follow safe practices by avoiding destructive flags.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a capability surface where external inputs (repository paths and branches) are ingested by the agent to perform actions.
  • Ingestion points: Repository paths and branch names provided by the operator or a registry (referenced in SKILL.md).
  • Boundary markers: The instructions do not specify explicit delimiters for path strings, but rely on standard shell variable handling.
  • Capability inventory: The skill uses cd and git commands to interact with the filesystem and remote repositories (referenced in SKILL.md).
  • Sanitization: The provided bash snippet does not show explicit path sanitization, but the doctrine requires manual operator intervention on conflicts and confirmation of repository paths, which acts as a human-in-the-loop control.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:39 AM