git-credentials

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the local environment which could theoretically be manipulated by an attacker.
  • Ingestion points: The scripts/check-git-auth.sh script ingests output from git remote -v and local filenames within the ~/.ssh directory.
  • Boundary markers: The script uses clear text headers such as remotes:, ssh_files:, and token_env_vars_set: to delimit data in the diagnostic report.
  • Capability inventory: The diagnostic script itself is read-only. The skill instructions for fixing issues (e.g., editing ~/.ssh/config or running gh auth login) are designed to be executed by the user with confirmation.
  • Sanitization: The script includes a robust sed filter to redact embedded credentials (passwords or tokens) from Git remote URLs before they are displayed or processed.
  • [COMMAND_EXECUTION]: The skill executes standard system utilities such as git, gh (GitHub CLI), sed, and stat to collect authentication metadata. These operations are restricted to gathering status information and do not involve executing arbitrary code or unsanitized input from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:05 AM
Security Audit — agent-trust-hub — git-credentials