skills/v1truv1us/ai-eng-system/why/Gen Agent Trust Hub

why

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands using git and the GitHub CLI (gh) to extract commit history, blame data, and Pull Request metadata.
  • [COMMAND_EXECUTION]: It leverages Model Context Protocol (MCP) servers to query external platforms such as Slack, Jira, Datadog, and Snowflake to retrieve historical context.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from well-known and trusted services, including GitHub repositories and official cloud-based product analytics warehouses.
  • [PROMPT_INJECTION]: Instructions include behavioral steering to adopt an investigative persona ('careful, cautious, and precise investigator') and strict output formatting rules to ensure objective, cited reporting.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is designed to access and aggregate internal organizational data (source control, tickets, chat, and docs). This is the intended functional purpose of the tool to provide design rationale and context to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 11:52 AM
Security Audit — agent-trust-hub — why