git-advanced
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform environment discovery by executing a directory listing command (
ls) on several skill-related paths in the user's home directory (e.g.,~/.claude/skills/,~/.agent/skills/) to identify which companion skills are currently installed. - [PROMPT_INJECTION]: The instructions include a behavior override requiring the agent to start its first response with a specific emoji (๐งข) once the skill is activated.
- [EXTERNAL_DOWNLOADS]: The skill recommends installing additional components from external sources using
npx skills add AbsolutelySkilled/AbsolutelySkilled. It also suggests installing third-party development tools likehusky,lint-staged, andcommitlintvia npm. - [REMOTE_CODE_EXECUTION]: The skill utilizes
npxfor various tasks (e.g.,npx husky init,npx lint-staged), which can download and execute packages from the npm registry at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core functionality.
- Ingestion points: The agent processes untrusted data from git repositories, including commit messages, branch names, and file contents, through commands such as
git log,git show, andgit bisect(documented inSKILL.mdandreferences/rebase-strategies.md). - Boundary markers: The skill lacks explicit instructions or delimiters to help the agent distinguish between legitimate git data and malicious instructions embedded in commit messages or repository history.
- Capability inventory: The skill has the capability to execute shell commands, configure git hooks, and perform package installations.
- Sanitization: There is no evidence of sanitization or filtering applied to external git content before it is processed by the agent.
Audit Metadata