githits-onboarding

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to fetch and execute the githits package from the NPM registry. This is a standard functional requirement for onboarding to the vendor's service and originates from the author's official package namespace.
  • [COMMAND_EXECUTION]: The skill executes shell commands to detect local agent configurations and install Model Context Protocol (MCP) components. These executions are scoped to the vendor's CLI tool and include instructions to avoid background tasks, ensuring user visibility and control over the process.
  • [CREDENTIALS_UNSAFE]: The instructions contain strong security guardrails, explicitly forbidding the agent from requesting, displaying, or collecting sensitive information such as passwords, OAuth codes, or API tokens within the chat session. It directs users to browser-based OAuth flows or local environment variables for secure authentication.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes JSON output from the GitHits CLI to determine setup status. While this creates a data ingestion surface, the risk is minimized by the skill's reliance on structured data from vendor-controlled tools and explicit classification logic for handling results.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 04:02 PM