dev-context-multi-repo
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary objective is to ingest large volumes of untrusted data from multiple repositories to create a context hub. This creates a significant ingestion surface for indirect instructions.
- Ingestion points:
scripts/scan_repo.pyreads repository files including READMEs and manifests;scripts/build_knowledge_graph.pyparses markdown tables and Mermaid diagrams from hub documents. - Boundary markers: The skill implements strict templates (e.g.,
assets/catalog-compiled-truth-template.md) that use horizontal rules and formal citation formats ([Source: ...]) to separate synthesized agent content from source evidence logs. - Capability inventory: The skill performs extensive file system read/write operations and utilizes
subprocessforgitcommands and internal tool orchestration across multiple Python scripts. - Sanitization: Ingested data is normalized into structured JSON; reporting tools in
scripts/export_graph_report.pyusehtml.escapeand regex-based sanitization for Mermaid diagram generation. - [COMMAND_EXECUTION]: Several scripts, including
scripts/build_artifact_set.py,scripts/scan_portfolio.py, andscripts/incremental_update.py, utilize thesubprocessmodule to execute tasks. - These calls are restricted to executing internal Python scripts within the skill or standard
gitcommands for analysis and change detection. No arbitrary shell execution on user-provided strings was detected. - [DYNAMIC_EXECUTION]: The regression test suite in
scripts/test_knowledge_graph_regressions.pyusesimportlib.utilto dynamically load the skill's local Python modules. - This implementation is used exclusively for testing purposes and is restricted to loading known local script files.
Audit Metadata