ship
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!syntax inSKILL.mdto executegit status --shortandgit diff --stat HEADwhen the skill is loaded. These are benign, read-only commands used to provide immediate repository status context to the agent and do not involve sensitive file access or network exfiltration. - [COMMAND_EXECUTION]: The skill instructs the agent to perform repository modifications and synchronization through shell commands including
git add,git commit, andgit pushto fulfill its primary purpose of git automation. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository's file changes (
git diff) and user-supplied input ($ARGUMENTS) to generate commit messages. - Ingestion points: Data enters the agent's context through the output of git status/diff commands and user arguments.
- Boundary markers: The instructions do not define specific delimiters to isolate the potentially untrusted diff content from the agent's instructions.
- Capability inventory: The skill has the capability to modify the local repository state and interact with remote repositories over the network.
- Sanitization: The instructions lack explicit logic for the agent to sanitize or escape the ingested diff content before it is used for message generation.
Audit Metadata