skills/rohitg00/pro-workflow/deslop/Gen Agent Trust Hub

deslop

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands like git fetch, git diff, and npm test. These are standard tools for code analysis and testing in development workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from git diffs and SKILL.md files, which acts as a vector for indirect prompt injection if those files contain malicious instructions hidden in comments or prose.
  • Ingestion points: The output of git diff and the contents of SKILL.md are directly analyzed by the agent.
  • Boundary markers: Absent; the skill does not provide clear delimiters or instructions to ignore embedded commands within the analyzed data.
  • Capability inventory: The agent has permissions to edit files and execute repository-level commands like git and npm.
  • Sanitization: Absent; the skill does not describe any validation or sanitization of the input diff before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — deslop