git
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill involve the execution of various Git commands (git rebase, git push, git fetch), GitHub CLI commands (gh pr view), and package management commands (pnpm install) as part of its documented workflows. These operations are within the expected scope of a Git management skill.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted data. 1. Ingestion points: Git history, commit messages, and PR metadata processed in SKILL.md. 2. Boundary markers: The skill emphasizes verification using pinned SHAs and ls-remote rather than trust. 3. Capability inventory: Execution of git, gh, and pnpm commands. 4. Sanitization: The skill recommends specific shell quoting techniques to prevent command interpolation in commit messages.
- [DYNAMIC_EXECUTION]: The skill provides instructions for non-interactive Git surgery and the use of shell heredocs for composing messages. It specifically warns the agent to use single-quoted heredocs (<<'EOF') to prevent the shell from executing backticks or dollar-sign expressions contained within the input, which is a key defense against command injection.
Audit Metadata