build-user-profile
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill uses shell commands to extract identity information from the workspace. Specifically, it executes
git log --all --format='%an <%ae>'to collect a list of unique names and email addresses from the repository history. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the workspace to influence the agent's collaboration behavior, creating a surface for injection attacks.
- Ingestion points: Processes workspace files including
*.yaml,*.yml, project manifests (package.json,requirements.txt, etc.), and documentation (READMEs, blog posts) as described in Step 1. - Boundary markers: No specific delimiters or "ignore instructions" warnings are utilized when processing content from these external files.
- Capability inventory: The skill is granted access to
Read,Write,Edit, andBashtools in the execution environment. - Sanitization: The skill does not perform validation or sanitization on the content gathered from the workspace before incorporating it into the synthesized user profile.
Audit Metadata