verify-and-ship
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by instructing the agent to fetch and strictly follow acceptance criteria from an external issue tracker.
- Ingestion points: The skill uses the
get_issuetool to ingest the issue description and acceptance criteria into the agent's context. - Boundary markers: Absent. There are no instructions to the agent to ignore potentially malicious commands embedded within the issue description.
- Capability inventory: The skill possesses significant capabilities, including executing shell commands, performing git operations (commit/push), and managing pull requests via GitHub and GitLab CLIs.
- Sanitization: Absent. The skill does not specify any sanitization or validation logic for the content retrieved from the issue tracker.
- [COMMAND_EXECUTION]: The skill relies on executing various shell commands to perform quality checks and repository management.
- Evidence: The instructions include shell commands for checking files (
ls), comparing changes (git diff), pushing code (git push), and interacting with platform-specific CLIs (gh pr,glab mr). These commands use variables (like branch names and PR titles) derived from the task context, which could be influenced by external input.
Audit Metadata