fish-shell-scripting
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill focuses on providing idiomatic development guidelines for Fish shell scripting.
- [CREDENTIALS_UNSAFE]: The documentation includes a dedicated section that strictly prohibits hardcoding secrets and provides safe alternatives such as machine-local authentication.
- [INDIRECT_PROMPT_INJECTION]: The skill features a robust 'Instruction Authority' section that mitigates indirect prompt injection by explicitly treating external data as untrusted and non-authoritative.
- [EXTERNAL_DOWNLOADS]: The skill defines a controlled process for fetching optional remote instructions from the author's verified GitHub repository, requiring user consent and content validation.
Audit Metadata