retro
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes and summarizes untrusted data from git logs, including commit messages and pull request titles. A maliciously crafted commit message could attempt to influence the agent's summary or narrative output.
- Ingestion points: Commit subjects (
%s), author names (%aN), and commit bodies extracted via variousgit logcommands inSKILL.md(Step 1). - Boundary markers: Absent. The instructions do not define clear delimiters or instructions to ignore embedded commands within the ingested commit data.
- Capability inventory: The skill can write files to the local
.context/retros/directory and execute shell commands via the git CLI. - Sanitization: Absent. The agent is instructed to interpret the data to write a narrative report without explicit sanitization steps.
- [DATA_EXFILTRATION]: The skill accesses the local git configuration to identify the current user for reporting purposes. While this data is used locally and not sent to an external service, it constitutes exposure of user identity information.
- Evidence:
git config user.nameandgit config user.emailare executed inSKILL.mdto distinguish 'your' commits from those of teammates.
Audit Metadata