chinese-git-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes instructions for managing Git credentials, such as using
git config credential.helper store. While this is a standard Git feature for maintaining authentication, it results in credentials being stored in plain text on the local filesystem. Similarly, it provides examples for configuring SSH keys (~/.ssh/config) for various platforms. - [EXTERNAL_DOWNLOADS]: The documentation references several well-known and legitimate Chinese developer platforms and mirrors, including Gitee, Coding.net, Jihulab (GitLab), CNB, and the official npmmirror registry for Node.js packages.
- [INDIRECT_PROMPT_INJECTION]: The skill provides structured templates for Commit messages and Pull Request descriptions that are designed to be filled with external, user-controlled data.
- Ingestion points: Commit message bodies and Pull Request description templates within SKILL.md.
- Boundary markers: No specific boundary markers or 'ignore' instructions are included in the provided templates.
- Capability inventory: None; the skill contains only markdown documentation and no executable tools or scripts.
- Sanitization: No sanitization or validation logic is present for the template fields.
Audit Metadata