ac-report

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from git commit messages which could contain malicious instructions designed to influence the agent's "beautification" and summarization process.
  • Ingestion points: Git log output (commit messages) ingested during the "Query commit records" step in SKILL.md.
  • Boundary markers: Absent; the instructions do not require the agent to use delimiters or specific safety instructions when processing the log content.
  • Capability inventory: Execution of Bash commands (git log, git config) and file reading (assets/templates/).
  • Sanitization: Absent; the skill provides no instructions to filter or sanitize the content of commit messages before they are processed by the model.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to construct and execute shell commands by interpolating user-provided parameters directly into command templates, creating a potential command injection surface.
  • Ingestion points: User input parameters (type, user, date) provided via the /ac-report command.
  • Boundary markers: Absent; the agent is not instructed to validate or escape these parameters.
  • Capability inventory: Shell command execution (git log --author="...").
  • Sanitization: Absent; there is no validation logic to ensure that user-provided strings (like a username containing shell metacharacters) do not alter the intended command structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:45 AM