skills/joydai2026-del/skills/ship-it/Gen Agent Trust Hub

ship-it

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the codebase, feature plans, and live web surfaces to determine its implementation and testing steps, which could allow malicious content in the codebase to influence agent behavior.\n
  • Ingestion points: Feature descriptions, codebase files, project plans, and live application outputs during the QA loop (Step 5).\n
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the data processed during the loop.\n
  • Capability inventory: The skill utilizes Bash for command execution, Write and Edit for file modifications, and the Agent tool for recursive task handling.\n
  • Sanitization: The instructions do not define methods for sanitizing or escaping content retrieved from the codebase or live surfaces before interpolation.\n- [COMMAND_EXECUTION]: The skill is designed for "hands-off" operation, explicitly instructing the agent not to ask for confirmation during intermediate steps. This autonomous execution of shell commands and code modifications increases the impact of potential logic errors or injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:35 AM
Security Audit — agent-trust-hub — ship-it