overleaf-sync
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute shell commands forgitoperations (pull, push, fetch, log) andrsyncfor local file synchronization between the bridge and working directories. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Remote content is ingested into the agent's environment via
git pullfrom Overleaf projects (SKILL.md). - Boundary markers: The skill lacks automated technical boundary markers for untrusted LaTeX content, relying instead on a behavioral "Diff protocol" for the agent.
- Capability inventory: The skill has access to
Bash(allowing network writes via git push),Write, andEdittools to modify local and remote files. - Sanitization: No automated sanitization is applied to the pulled content; the agent is instructed to manually review diffs for suspicious or low-quality changes.
- [CREDENTIALS_UNSAFE]: While the skill promotes secure practices like OS keychain storage, it explicitly handles and describes Overleaf authentication token patterns (
olp_...). It relies on a behavioral rule and a custompre-commithook to prevent these tokens from being leaked in chat history or git commits, representing a credential management surface.
Audit Metadata