ship
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions promote secure coding practices by explicitly forbidding the commitment of secrets, local environment files, and logs.
- [COMMAND_EXECUTION]: The skill utilizes standard development tools such as
git,gh(GitHub CLI), and common testing/build commands (npm test,lint). These operations are aligned with the skill's primary purpose of publishing code changes and do not involve arbitrary or hidden command execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data in the form of git diffs and commit messages.
- Ingestion points: Reads output from
git status, unstaged/staged diffs, and recent commits (SKILL.md). - Boundary markers: Includes instructions to explicitly state the shipment scope and verify intended changes before staging, which acts as a manual boundary (SKILL.md).
- Capability inventory: Uses
git,gh, and project-specific testing/build tools (SKILL.md). - Sanitization: Relies on the user to review the agent's reported scope and the agent's internal logic to filter out unrelated or sensitive files.
Audit Metadata