dev-context-multi-repo

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary objective is to ingest large volumes of untrusted data from multiple repositories to create a context hub. This creates a significant ingestion surface for indirect instructions.
  • Ingestion points: scripts/scan_repo.py reads repository files including READMEs and manifests; scripts/build_knowledge_graph.py parses markdown tables and Mermaid diagrams from hub documents.
  • Boundary markers: The skill implements strict templates (e.g., assets/catalog-compiled-truth-template.md) that use horizontal rules and formal citation formats ([Source: ...]) to separate synthesized agent content from source evidence logs.
  • Capability inventory: The skill performs extensive file system read/write operations and utilizes subprocess for git commands and internal tool orchestration across multiple Python scripts.
  • Sanitization: Ingested data is normalized into structured JSON; reporting tools in scripts/export_graph_report.py use html.escape and regex-based sanitization for Mermaid diagram generation.
  • [COMMAND_EXECUTION]: Several scripts, including scripts/build_artifact_set.py, scripts/scan_portfolio.py, and scripts/incremental_update.py, utilize the subprocess module to execute tasks.
  • These calls are restricted to executing internal Python scripts within the skill or standard git commands for analysis and change detection. No arbitrary shell execution on user-provided strings was detected.
  • [DYNAMIC_EXECUTION]: The regression test suite in scripts/test_knowledge_graph_regressions.py uses importlib.util to dynamically load the skill's local Python modules.
  • This implementation is used exclusively for testing purposes and is restricted to loading known local script files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:20 PM
Security Audit — agent-trust-hub — dev-context-multi-repo