kmp-roborazzi

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a utility script scripts/pr_visual_evidence.py that interacts with the local environment by executing git commands (git diff, git rev-parse, git remote, git cat-file) to analyze changes in visual snapshots. The implementation uses subprocess.run with argument lists rather than shell strings, which is a secure practice to prevent shell injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface where untrusted data from the repository is processed to generate automated reports.
  • Ingestion points: File paths and git status codes are read from the repository's git history and file system by scripts/pr_visual_evidence.py.
  • Boundary markers: The script does not include explicit delimiters or safety instructions in the generated Markdown output to prevent downstream agents or users from misinterpreting maliciously crafted file names.
  • Capability inventory: The script facilitates the generation of pull request bodies that integrate data from external repository contributors.
  • Sanitization: Although the script correctly escapes URL components using urllib.parse.quote, the file paths themselves are inserted into HTML <code> elements and alt tags within the Markdown output without additional sanitization or escaping of characters that might influence Markdown rendering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:23 AM
Security Audit — agent-trust-hub — kmp-roborazzi