git-advanced

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform environment discovery by executing a directory listing command (ls) on several skill-related paths in the user's home directory (e.g., ~/.claude/skills/, ~/.agent/skills/) to identify which companion skills are currently installed.
  • [PROMPT_INJECTION]: The instructions include a behavior override requiring the agent to start its first response with a specific emoji (๐Ÿงข) once the skill is activated.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing additional components from external sources using npx skills add AbsolutelySkilled/AbsolutelySkilled. It also suggests installing third-party development tools like husky, lint-staged, and commitlint via npm.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes npx for various tasks (e.g., npx husky init, npx lint-staged), which can download and execute packages from the npm registry at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core functionality.
  • Ingestion points: The agent processes untrusted data from git repositories, including commit messages, branch names, and file contents, through commands such as git log, git show, and git bisect (documented in SKILL.md and references/rebase-strategies.md).
  • Boundary markers: The skill lacks explicit instructions or delimiters to help the agent distinguish between legitimate git data and malicious instructions embedded in commit messages or repository history.
  • Capability inventory: The skill has the capability to execute shell commands, configure git hooks, and perform package installations.
  • Sanitization: There is no evidence of sanitization or filtering applied to external git content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit โ€” agent-trust-hub โ€” git-advanced