synrepo

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill manages a potential indirect prompt injection surface where untrusted repository data is processed.
  • Ingestion points: Repository files and overlay commentary (SKILL.md).
  • Boundary markers: Present; instructions specify that overlay commentary, explain docs, and proposed cross-links are advisory and should not be treated as canonical source truth.
  • Capability inventory: Search, read, and potential source mutation via synrepo_apply_anchor_edits across various skill tools.
  • Sanitization: Relies on the external synrepo tool logic and explicit agent instructions to prioritize authoritative graph facts over advisory content.
  • [COMMAND_EXECUTION]: The skill uses local synrepo CLI commands for repository analysis. All mentioned commands and flags (such as --allow-source-edits) are standard for the tool's documented purpose.
  • [DATA_EXFILTRATION]: No exfiltration patterns or network requests to non-whitelisted domains were detected; operations are restricted to the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 06:22 PM
Security Audit — agent-trust-hub — synrepo