git-workflow-and-versioning
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively provides instructional content for Git best practices, branch management, and Semantic Versioning (SemVer).
- [SAFE]: It encourages security hygiene by providing patterns to check for secrets (passwords, API keys, tokens) in staged diffs before committing.
- [SAFE]: It promotes the use of
.gitignoreto exclude sensitive files like.envand*.pemfrom version control. - [SAFE]: No suspicious external downloads, remote code execution, or data exfiltration patterns were identified. All shell commands provided (e.g., git worktree, git bisect) are standard developer tools used for their intended purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill describes workflows involving reading git logs, diffs, and blame information which could theoretically contain malicious instructions if a repository is compromised; however, this is an inherent property of version control systems and the skill provides no dangerous automated execution path for such content.
- Ingestion points: Git history tools (
git log,git diff,git blame). - Boundary markers: None specific; manual review is implied by the workflow.
- Capability inventory: Git commands, standard Node.js development tools (
npm,npx). - Sanitization: Not applicable as content is for human/agent review during development.
Audit Metadata