git-credentials
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the local environment which could theoretically be manipulated by an attacker.
- Ingestion points: The
scripts/check-git-auth.shscript ingests output fromgit remote -vand local filenames within the~/.sshdirectory. - Boundary markers: The script uses clear text headers such as
remotes:,ssh_files:, andtoken_env_vars_set:to delimit data in the diagnostic report. - Capability inventory: The diagnostic script itself is read-only. The skill instructions for fixing issues (e.g., editing
~/.ssh/configor runninggh auth login) are designed to be executed by the user with confirmation. - Sanitization: The script includes a robust
sedfilter to redact embedded credentials (passwords or tokens) from Git remote URLs before they are displayed or processed. - [COMMAND_EXECUTION]: The skill executes standard system utilities such as
git,gh(GitHub CLI),sed, andstatto collect authentication metadata. These operations are restricted to gathering status information and do not involve executing arbitrary code or unsanitized input from external sources.
Audit Metadata