synrepo
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill manages a potential indirect prompt injection surface where untrusted repository data is processed.
- Ingestion points: Repository files and overlay commentary (SKILL.md).
- Boundary markers: Present; instructions specify that overlay commentary, explain docs, and proposed cross-links are advisory and should not be treated as canonical source truth.
- Capability inventory: Search, read, and potential source mutation via
synrepo_apply_anchor_editsacross various skill tools. - Sanitization: Relies on the external
synrepotool logic and explicit agent instructions to prioritize authoritative graph facts over advisory content. - [COMMAND_EXECUTION]: The skill uses local
synrepoCLI commands for repository analysis. All mentioned commands and flags (such as--allow-source-edits) are standard for the tool's documented purpose. - [DATA_EXFILTRATION]: No exfiltration patterns or network requests to non-whitelisted domains were detected; operations are restricted to the local environment.
Audit Metadata