ship-release-candidate
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of shell commands to interact with the local and remote repository environment.
- Evidence: Uses
git fetch,git diff,git log,git push, andgh pr createto manage branches and PRs. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from sources that may be controlled by third-party contributors, creating a surface for indirect instructions to influence the agent.
- Ingestion points: Retrieves commit messages via
git log, code changes viagit diff, and repository-specific configuration from.github/pull_request_template.md(SKILL.md). - Boundary markers: Absent; the skill does not use specific delimiters or instructions to prevent the agent from following commands embedded in commit messages or diffs.
- Capability inventory: The skill has the authority to push code to remote branches (
git push) and create pull requests (gh pr create), which could be abused if the agent follows instructions found in logs. - Sanitization: No sanitization, escaping, or validation is performed on the commit history or diff content before it is interpolated into the final PR body.
- [PROMPT_INJECTION]: The instructions contain directives to override default agent behavior regarding transparency and attribution.
- Evidence: The section "No agentic annotations — ever" explicitly commands the agent to strip and remove AI-related watermarks,
Co-authored-bylines referencing AI tools, and any other indicators of agentic attribution from commit messages and PR bodies.
Audit Metadata