skills/h00mankind/workflow/ship/Gen Agent Trust Hub

ship

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions promote secure coding practices by explicitly forbidding the commitment of secrets, local environment files, and logs.
  • [COMMAND_EXECUTION]: The skill utilizes standard development tools such as git, gh (GitHub CLI), and common testing/build commands (npm test, lint). These operations are aligned with the skill's primary purpose of publishing code changes and do not involve arbitrary or hidden command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data in the form of git diffs and commit messages.
  • Ingestion points: Reads output from git status, unstaged/staged diffs, and recent commits (SKILL.md).
  • Boundary markers: Includes instructions to explicitly state the shipment scope and verify intended changes before staging, which acts as a manual boundary (SKILL.md).
  • Capability inventory: Uses git, gh, and project-specific testing/build tools (SKILL.md).
  • Sanitization: Relies on the user to review the agent's reported scope and the agent's internal logic to filter out unrelated or sensitive files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 02:53 AM
Security Audit — agent-trust-hub — ship