ship
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses multiple shell commands to manage repository state, including
git merge,git push,git branch -D(destructive deletion), andgh pr create. These commands are necessary for the skill's purpose but require user trust in the agent's actions. - [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface for indirect prompt injection because it processes untrusted data from the repository's history and diffs.
- Ingestion points: The skill reads output from
git logandgit diffduring safety checks and when generating pull request bodies. It also reads configuration from02-DOCS/wiki/sdd/config.yamland user profiles. - Boundary markers: There are no explicit delimiters or instructions to help the agent distinguish between data and instructions when processing git history.
- Capability inventory: The agent can perform significant repository changes, including deleting local and remote branches and pushing new commits.
- Sanitization: The skill does not appear to sanitize data extracted from the repository before using it to construct commit messages or pull request descriptions.
- [EXTERNAL_DOWNLOADS]: The skill references the execution of tools via
npx, which involves downloading and running packages from the NPM registry. - Evidence:
SKILL.mdmentionsnpx @ericrisco/rsc sello offandnpx @ericrisco/rsc worktrees. - Note: These packages are scoped to the skill's author ('ericrisco') and represent expected vendor-provided functionality.
Audit Metadata