dev-contribution-quality-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/sample-code-quality.pyutilizessubprocess.run()to execute standardgitcommands for repository analysis. The commands are constructed using argument lists, which is a secure practice to prevent shell injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data, specifically git commit history and CSV files. This creates an indirect injection surface where malicious content in commit messages could potentially influence downstream agent interpretations of the generated quality reports.
- Ingestion points: CSV files (
raw-commits.csv,mr-acceptances.csv) and git repository logs viagit show(found inscripts/extract-contribution-profile.pyandscripts/sample-code-quality.py). - Boundary markers: The reports use clear headers and structured sections, though they do not explicitly include "ignore embedded instructions" warnings for processed commit subjects.
- Capability inventory: The skill performs file writing, CSV parsing, and subprocess calls to the
gitCLI (found inscripts/sample-code-quality.py). - Sanitization: Standard CSV and git log parsing is performed; no specialized LLM-focused sanitization of commit messages or subjects is present.
Audit Metadata