githits-code

Pass

Audited by Gen Agent Trust Hub on Oct 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from public repositories and documentation sites, which could contain malicious instructions. However, the skill includes a dedicated 'External Content Posture' section that explicitly instructs the agent to treat all retrieved data as untrusted evidence and to ignore any embedded commands or directions.
  • Ingestion points: githits search, githits read, and githits grep commands in SKILL.md ingest external source code and documentation.
  • Boundary markers: The 'External Content Posture' section in SKILL.md provides explicit behavioral instructions to ignore embedded directions.
  • Capability inventory: The skill utilizes the githits CLI for repository analysis and file reading, as described in SKILL.md and references/code-and-docs.md.
  • Sanitization: Instructions mandate verifying all claims against structured fields and tool-owned provenance rather than adopting data-driven directions.
  • [REMOTE_CODE_EXECUTION]: The skill suggests using npx -y githits@latest as a fallback if the local binary is unavailable. This involves downloading and executing the githits package from the NPM registry. This is the intended primary purpose of the skill, and the package is a resource belonging to the skill's author.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 10, 2026, 03:35 AM