verify-and-ship

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by instructing the agent to fetch and strictly follow acceptance criteria from an external issue tracker.
  • Ingestion points: The skill uses the get_issue tool to ingest the issue description and acceptance criteria into the agent's context.
  • Boundary markers: Absent. There are no instructions to the agent to ignore potentially malicious commands embedded within the issue description.
  • Capability inventory: The skill possesses significant capabilities, including executing shell commands, performing git operations (commit/push), and managing pull requests via GitHub and GitLab CLIs.
  • Sanitization: Absent. The skill does not specify any sanitization or validation logic for the content retrieved from the issue tracker.
  • [COMMAND_EXECUTION]: The skill relies on executing various shell commands to perform quality checks and repository management.
  • Evidence: The instructions include shell commands for checking files (ls), comparing changes (git diff), pushing code (git push), and interacting with platform-specific CLIs (gh pr, glab mr). These commands use variables (like branch names and PR titles) derived from the task context, which could be influenced by external input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:49 PM
Security Audit — agent-trust-hub — verify-and-ship