githits-code
Pass
Audited by Gen Agent Trust Hub on Oct 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from public repositories and documentation sites, which could contain malicious instructions. However, the skill includes a dedicated 'External Content Posture' section that explicitly instructs the agent to treat all retrieved data as untrusted evidence and to ignore any embedded commands or directions.
- Ingestion points:
githits search,githits read, andgithits grepcommands inSKILL.mdingest external source code and documentation. - Boundary markers: The 'External Content Posture' section in
SKILL.mdprovides explicit behavioral instructions to ignore embedded directions. - Capability inventory: The skill utilizes the
githitsCLI for repository analysis and file reading, as described inSKILL.mdandreferences/code-and-docs.md. - Sanitization: Instructions mandate verifying all claims against structured fields and tool-owned provenance rather than adopting data-driven directions.
- [REMOTE_CODE_EXECUTION]: The skill suggests using
npx -y githits@latestas a fallback if the local binary is unavailable. This involves downloading and executing thegithitspackage from the NPM registry. This is the intended primary purpose of the skill, and the package is a resource belonging to the skill's author.
Audit Metadata