skill-draft-ship
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
git rev-parse --show-toplevelto define the repository root and invokes the repository-local toolmethodology-skill-creatorto generate draft content.\n- [PROMPT_INJECTION]: The skill acts as an indirect prompt injection surface by converting user-supplied metadata into skill definitions. Ingestion points: User-provided checklist during draft initialization in theSKILL.mdfile. Boundary markers: Strict input contracts, explicit human-in-the-loop requirements for ship operations, and prohibited writes outside the repository root. Capability inventory: File system write access for skill packaging, local script execution for content generation, and repository discovery commands. Sanitization: Relies on mandatory human review of the generated proposal and explicit ship confirmation to verify artifacts before they are persisted in the production environment.
Audit Metadata