git-history-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from git logs and commit messages, which presents a surface for instructions to be embedded in the repository history.
  • Ingestion points: Data retrieved via git log and git blame (SKILL.md).
  • Boundary markers: Absent; there are no delimiters used to separate the analyzed data from the agent's instructions.
  • Capability inventory: Shell execution of git commands and pattern searching (SKILL.md).
  • Sanitization: Absent; the skill does not specify any validation or filtering of the content retrieved from the git history.
  • [COMMAND_EXECUTION]: The skill is designed to execute various shell commands to retrieve repository metadata and history.
  • Evidence: Explicit instructions to use git log, git blame, and git shortlog commands (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:02 PM
Security Audit — agent-trust-hub — git-history-analyzer