git-workflows
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions involve reading data from external, potentially attacker-controlled sources such as GitHub issues and pull requests, which creates an indirect prompt injection surface.
- Ingestion points: GitHub issue lists and pull request content via the gh and gw tools in SKILL.md.
- Boundary markers: No delimiters or explicit instructions to ignore embedded commands are included in the documentation.
- Capability inventory: The skill can perform write and network operations including git commit, git push, and gh pr merge.
- Sanitization: No sanitization or validation of the retrieved external content is specified.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill includes a 'Best Practices' section that explicitly instructs the agent to avoid committing secrets, .env files, or API keys, which serves as a positive security control.
Audit Metadata