ship-release-candidate

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell commands to interact with the local and remote repository environment.
  • Evidence: Uses git fetch, git diff, git log, git push, and gh pr create to manage branches and PRs.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from sources that may be controlled by third-party contributors, creating a surface for indirect instructions to influence the agent.
  • Ingestion points: Retrieves commit messages via git log, code changes via git diff, and repository-specific configuration from .github/pull_request_template.md (SKILL.md).
  • Boundary markers: Absent; the skill does not use specific delimiters or instructions to prevent the agent from following commands embedded in commit messages or diffs.
  • Capability inventory: The skill has the authority to push code to remote branches (git push) and create pull requests (gh pr create), which could be abused if the agent follows instructions found in logs.
  • Sanitization: No sanitization, escaping, or validation is performed on the commit history or diff content before it is interpolated into the final PR body.
  • [PROMPT_INJECTION]: The instructions contain directives to override default agent behavior regarding transparency and attribution.
  • Evidence: The section "No agentic annotations — ever" explicitly commands the agent to strip and remove AI-related watermarks, Co-authored-by lines referencing AI tools, and any other indicators of agentic attribution from commit messages and PR bodies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — ship-release-candidate