git-workflow-and-versioning

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exclusively provides instructional content for Git best practices, branch management, and Semantic Versioning (SemVer).
  • [SAFE]: It encourages security hygiene by providing patterns to check for secrets (passwords, API keys, tokens) in staged diffs before committing.
  • [SAFE]: It promotes the use of .gitignore to exclude sensitive files like .env and *.pem from version control.
  • [SAFE]: No suspicious external downloads, remote code execution, or data exfiltration patterns were identified. All shell commands provided (e.g., git worktree, git bisect) are standard developer tools used for their intended purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes workflows involving reading git logs, diffs, and blame information which could theoretically contain malicious instructions if a repository is compromised; however, this is an inherent property of version control systems and the skill provides no dangerous automated execution path for such content.
  • Ingestion points: Git history tools (git log, git diff, git blame).
  • Boundary markers: None specific; manual review is implied by the workflow.
  • Capability inventory: Git commands, standard Node.js development tools (npm, npx).
  • Sanitization: Not applicable as content is for human/agent review during development.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — git-workflow-and-versioning