conductor-revert

Warn

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell command interpolation using user-provided variables such as {trackId} and {X.Y} within commands like git log --oneline --grep="{trackId}". If these identifiers are sourced from untrusted user input or malicious files and contain shell metacharacters (e.g., ;, |, or &), an attacker could execute arbitrary code on the host system.
  • [SAFE]: The skill mandates safe Git practices by using git revert exclusively rather than destructive history-rewriting commands like git reset --hard or git push --force.
  • [SAFE]: A strict, case-sensitive confirmation step is enforced, requiring the user to type 'YES' exactly before proceeding with the revert execution plan, which helps prevent accidental or automated operations.
  • [SAFE]: The instructions include clear failure handling, requiring the agent to halt immediately if merge conflicts occur or if the environment is not in a clean state, ensuring human intervention for complex resolution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 9, 2026, 02:37 PM
Security Audit — agent-trust-hub — conductor-revert