guardian
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of Git and GitHub CLI (
gh) commands to manage repository states, including creating branches, rewriting history (git rebase,git merge --squash), and merging pull requests. These operations have the potential to destructively modify repository data or bypass intended workflows if misused. - [REMOTE_CODE_EXECUTION]: Several recipes (e.g.,
git-recipes.md,ship) suggest executing local repository scripts such asnpm run buildandnpm test, as well as package managers likenpm install. These commands execute code defined within the target repository's configuration files, which could lead to arbitrary code execution if the repository contains malicious scripts. - [PRIVILEGE_ESCALATION]: The
shiprecipe includes functionality to use the--adminflag withgh pr merge. This allows the agent to bypass branch protection rules (e.g., required reviews or passing status checks) set within the GitHub organization. The skill correctly identifies this as an 'Ask First' operation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from Git commit messages and code diffs. A malicious actor could craft commits containing instructions aimed at influencing the agent's analysis, such as quality grades or risk assessments. The instructions do not explicitly detail sanitization or isolation protocols for this external content.
Audit Metadata