research-git
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves fetching and analyzing untrusted content from public repositories (SKILL.md files, source code, CI configurations) which could contain malicious instructions or deceptive content.
- Ingestion points: The
scripts/fetch_repo_assets.shscript programmatically fetches files from external repositories into thedocs/research/directory. - Boundary markers: The
references/attribution-rules.mdandreferences/apply-protocol.mdfiles establish boundaries by requiring manual user approval and explicit attribution for all extracted insights. - Capability inventory: The skill utilizes
ghCLI,git,curl, andjqfor data retrieval and processing, with the ability to write to the local filesystem. - Sanitization: The instructions specifically mandate that the agent must rewrite all extracted patterns in a 'local voice' rather than copying verbatim, acting as a manual sanitization step for ingested text.
- [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch repository data, metadata, and security signals from several well-known developer services.
- Evidence: The scripts and documentation reference interactions with
github.com,api.scorecard.dev(OpenSSF Scorecard),ossinsight.io,api.deps.dev(Google OS Insights),libraries.io,sourcegraph.com, andgitlab.com. - Trust Scope: These services are recognized as established developer infrastructure and are used for their intended research purposes.
- [COMMAND_EXECUTION]: The skill relies on executing system commands to perform its research tasks.
- Evidence: The
scripts/directory contains bash scripts that invokegh,git,jq,curl, andbase64as subprocesses to search for repos, fetch assets, and perform history forensics.
Audit Metadata