overleaf-sync

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute shell commands for git operations (pull, push, fetch, log) and rsync for local file synchronization between the bridge and working directories.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Remote content is ingested into the agent's environment via git pull from Overleaf projects (SKILL.md).
  • Boundary markers: The skill lacks automated technical boundary markers for untrusted LaTeX content, relying instead on a behavioral "Diff protocol" for the agent.
  • Capability inventory: The skill has access to Bash (allowing network writes via git push), Write, and Edit tools to modify local and remote files.
  • Sanitization: No automated sanitization is applied to the pulled content; the agent is instructed to manually review diffs for suspicious or low-quality changes.
  • [CREDENTIALS_UNSAFE]: While the skill promotes secure practices like OS keychain storage, it explicitly handles and describes Overleaf authentication token patterns (olp_...). It relies on a behavioral rule and a custom pre-commit hook to prevent these tokens from being leaked in chat history or git commits, representing a credential management surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 02:42 PM
Security Audit — agent-trust-hub — overleaf-sync