skills/terrylica/cc-skills/auto-sync/Gen Agent Trust Hub

auto-sync

Warn

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to install a post-commit git hook. This creates a persistence mechanism where the graphify command is executed automatically every time a commit is made, which runs code outside of the immediate agent session.
  • [PROMPT_INJECTION]: The skill includes a 'Self-Evolving' directive and 'Post-Execution Reflection' section that commands the agent to autonomously modify its own SKILL.md file. This instruction for the agent to rewrite its own logic and constraints based on runtime experiences allows for behavioral drift and could be exploited to bypass intended security or operational boundaries over time.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 24, 2026, 11:24 AM
Security Audit — agent-trust-hub — auto-sync