skills/devjuanp/skills/ship/Gen Agent Trust Hub

ship

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax in SKILL.md to execute git status --short and git diff --stat HEAD when the skill is loaded. These are benign, read-only commands used to provide immediate repository status context to the agent and do not involve sensitive file access or network exfiltration.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform repository modifications and synchronization through shell commands including git add, git commit, and git push to fulfill its primary purpose of git automation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository's file changes (git diff) and user-supplied input ($ARGUMENTS) to generate commit messages.
  • Ingestion points: Data enters the agent's context through the output of git status/diff commands and user arguments.
  • Boundary markers: The instructions do not define specific delimiters to isolate the potentially untrusted diff content from the agent's instructions.
  • Capability inventory: The skill has the capability to modify the local repository state and interact with remote repositories over the network.
  • Sanitization: The instructions lack explicit logic for the agent to sanitize or escape the ingested diff content before it is used for message generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 07:16 AM
Security Audit — agent-trust-hub — ship