ship

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The instructions include a directive to prioritize the local 'RNA pipeline' over 'generic Open Horizons guidance,' which functions as a direct instruction override.
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by processing external data from Pull Requests.
  • Ingestion points: The agent ingests Pull Request content (identified by PR number) and reads sequential instructions from the file '.claude/agents/ship.md'.
  • Boundary markers: No delimiters or safety instructions are defined to separate the agent's core instructions from potentially malicious content within the PR.
  • Capability inventory: The skill authorizes the agent to post findings, leave comments, and perform merges on Pull Requests.
  • Sanitization: There is no evidence of filtering or validation for the ingested external content or the referenced configuration file.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and does not include any accompanying scripts or executable files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 04:54 PM
Security Audit — agent-trust-hub — ship