git
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: The skill ingests data from external sources via
gh issue view(including full comment threads) and audits file contents during triage and sanitization phases. - Boundary markers: Absent. The skill relies on the agent's internal reasoning to classify content using the '9-Tier Anti-Slop' taxonomy rather than using structural delimiters to isolate external data from instructions.
- Capability inventory: The skill has significant capabilities, including access to the
bashandrun_commandtools, the ability to write to files, and the capability to push/delete remote Git branches. - Sanitization: Absent. There is no evidence that the skill sanitizes or escapes external content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill frequently executes shell commands in the workspace environment, which is a necessary but sensitive capability.
- Evidence: The skill automatically executes package management commands (
bun install,npm install,cargo check,uv sync, etc.) and workspace-local scripts (e.g.,ai-ready.ts). If the repository being managed contains malicious configuration files (likepackage.jsonscripts), these operations could result in unintended code execution within the agent's environment.
Audit Metadata