skills/ericrisco/rsc-harness/ship/Gen Agent Trust Hub

ship

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses multiple shell commands to manage repository state, including git merge, git push, git branch -D (destructive deletion), and gh pr create. These commands are necessary for the skill's purpose but require user trust in the agent's actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface for indirect prompt injection because it processes untrusted data from the repository's history and diffs.
  • Ingestion points: The skill reads output from git log and git diff during safety checks and when generating pull request bodies. It also reads configuration from 02-DOCS/wiki/sdd/config.yaml and user profiles.
  • Boundary markers: There are no explicit delimiters or instructions to help the agent distinguish between data and instructions when processing git history.
  • Capability inventory: The agent can perform significant repository changes, including deleting local and remote branches and pushing new commits.
  • Sanitization: The skill does not appear to sanitize data extracted from the repository before using it to construct commit messages or pull request descriptions.
  • [EXTERNAL_DOWNLOADS]: The skill references the execution of tools via npx, which involves downloading and running packages from the NPM registry.
  • Evidence: SKILL.md mentions npx @ericrisco/rsc sello off and npx @ericrisco/rsc worktrees.
  • Note: These packages are scoped to the skill's author ('ericrisco') and represent expected vendor-provided functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — ship