ln-001-push-all
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches reference files and configuration guidelines from the author's public GitHub repository when local versions are missing.
- [COMMAND_EXECUTION]: Executes Git commands and dynamically discovered linter commands based on project documentation.
- [DATA_EXFILTRATION]: Transfers local source code to the configured remote repository as its primary function.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection during linter command discovery.
- Ingestion points: Reads configuration from
docs/project/runbook.md,CLAUDE.md,README.md,CONTRIBUTING.md, andci_tool_detection.md. - Boundary markers: Absent; the skill does not define specific delimiters to separate data from instructions.
- Capability inventory: Executes shell commands (linters) identified in Phase 4 across all scripts.
- Sanitization: Absent; there is no validation or escaping mentioned for the discovered linter commands.
Audit Metadata