chinese-git-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill includes instructions for managing Git credentials, such as using git config credential.helper store. While this is a standard Git feature for maintaining authentication, it results in credentials being stored in plain text on the local filesystem. Similarly, it provides examples for configuring SSH keys (~/.ssh/config) for various platforms.
  • [EXTERNAL_DOWNLOADS]: The documentation references several well-known and legitimate Chinese developer platforms and mirrors, including Gitee, Coding.net, Jihulab (GitLab), CNB, and the official npmmirror registry for Node.js packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides structured templates for Commit messages and Pull Request descriptions that are designed to be filled with external, user-controlled data.
  • Ingestion points: Commit message bodies and Pull Request description templates within SKILL.md.
  • Boundary markers: No specific boundary markers or 'ignore' instructions are included in the provided templates.
  • Capability inventory: None; the skill contains only markdown documentation and no executable tools or scripts.
  • Sanitization: No sanitization or validation logic is present for the template fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:47 AM