build-user-profile

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill uses shell commands to extract identity information from the workspace. Specifically, it executes git log --all --format='%an <%ae>' to collect a list of unique names and email addresses from the repository history.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the workspace to influence the agent's collaboration behavior, creating a surface for injection attacks.
  • Ingestion points: Processes workspace files including *.yaml, *.yml, project manifests (package.json, requirements.txt, etc.), and documentation (READMEs, blog posts) as described in Step 1.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are utilized when processing content from these external files.
  • Capability inventory: The skill is granted access to Read, Write, Edit, and Bash tools in the execution environment.
  • Sanitization: The skill does not perform validation or sanitization on the content gathered from the workspace before incorporating it into the synthesized user profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 12:13 AM
Security Audit — agent-trust-hub — build-user-profile