setup-qquirk-skills

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions for using standard command-line interfaces such as git, gh (GitHub CLI), and glab (GitLab CLI) to manage issues, pull requests, and repository metadata. These operations are within the scope of the skill's purpose and follow best practices for repository management.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local repository files, such as .git/config, AGENTS.md, and CLAUDE.md, to determine the current configuration state. While these files are local and typically user-controlled, they represent a potential surface for indirect instructions. However, the skill mitigates this by presenting exploration findings to the user for confirmation before taking action.
  • [DATA_EXPOSURE]: Exploration includes reading Git remote configurations and repository metadata to identify the hosting provider and project structure. This information is used solely to select appropriate templates and does not involve exfiltrating sensitive information to untrusted third parties.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:59 AM
Security Audit — agent-trust-hub — setup-qquirk-skills