ship-checklist
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard procedural checklist for site validation. It does not perform network operations, execute arbitrary code, or access sensitive system files.
- [PROMPT_INJECTION]: The skill ingests data from project files such as IA.md and TRACKING.md to verify implementation status. While these are external ingestion points, the risk is negligible as the skill lacks dangerous capabilities and model invocation is disabled. 1. Ingestion points: IA.md, TRACKING.md, and docs/agents/analytics.md; 2. Boundary markers: Absent; 3. Capability inventory: File reading and repo exploration; 4. Sanitization: Absent.
Audit Metadata