kmp-roborazzi
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a utility script
scripts/pr_visual_evidence.pythat interacts with the local environment by executinggitcommands (git diff,git rev-parse,git remote,git cat-file) to analyze changes in visual snapshots. The implementation usessubprocess.runwith argument lists rather than shell strings, which is a secure practice to prevent shell injection. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface where untrusted data from the repository is processed to generate automated reports.
- Ingestion points: File paths and git status codes are read from the repository's git history and file system by
scripts/pr_visual_evidence.py. - Boundary markers: The script does not include explicit delimiters or safety instructions in the generated Markdown output to prevent downstream agents or users from misinterpreting maliciously crafted file names.
- Capability inventory: The script facilitates the generation of pull request bodies that integrate data from external repository contributors.
- Sanitization: Although the script correctly escapes URL components using
urllib.parse.quote, the file paths themselves are inserted into HTML<code>elements andalttags within the Markdown output without additional sanitization or escaping of characters that might influence Markdown rendering.
Audit Metadata