dev-contribution-quality-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/sample-code-quality.py utilizes subprocess.run() to execute standard git commands for repository analysis. The commands are constructed using argument lists, which is a secure practice to prevent shell injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data, specifically git commit history and CSV files. This creates an indirect injection surface where malicious content in commit messages could potentially influence downstream agent interpretations of the generated quality reports.
  • Ingestion points: CSV files (raw-commits.csv, mr-acceptances.csv) and git repository logs via git show (found in scripts/extract-contribution-profile.py and scripts/sample-code-quality.py).
  • Boundary markers: The reports use clear headers and structured sections, though they do not explicitly include "ignore embedded instructions" warnings for processed commit subjects.
  • Capability inventory: The skill performs file writing, CSV parsing, and subprocess calls to the git CLI (found in scripts/sample-code-quality.py).
  • Sanitization: Standard CSV and git log parsing is performed; no specialized LLM-focused sanitization of commit messages or subjects is present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — dev-contribution-quality-analysis