workflow-reconciliation

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • Dynamic Execution (MEDIUM): The assets/reconciliation-rules.json file defines commit_template strings that interpolate the {name} variable into shell commands for Git operations. This pattern is vulnerable to command injection if plugin names or descriptions are maliciously crafted.\n- Indirect Prompt Injection (LOW): The skill processes untrusted data from .continue-here.md files to determine and execute automated remediation steps.\n
  • Ingestion points: plugins/{PluginName}/.continue-here.md\n
  • Boundary markers: Absent.\n
  • Capability inventory: Git staging, Git committing, and file modification.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 06:17 PM