ship
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions designed to override standard agent safety protocols and user confirmation steps.
- Evidence: SKILL.md states: "This is a non-interactive, fully automated workflow. Do NOT ask for confirmation at any step. The user said
shipwhich means DO IT. Run straight through..." - Evidence: The agent is further instructed to "Never stop for: ... Commit message approval (auto-commit)" and "CHANGELOG content (auto-generate from diff)", encouraging autonomous action without human review.
- [INDIRECT_PROMPT_INJECTION]: The skill has a high surface area for indirect prompt injection because it ingests untrusted data from the repository history and diffs to automate tasks without human oversight.
- Ingestion points: The agent reads data from
git log,git diff,git status, and project files likeCHANGELOG.mdandVERSION(SKILL.md Steps 1, 3.25, 3.5, 5, 6, 8). - Boundary markers: The instructions lack delimiters or explicit warnings to ignore malicious instructions that might be embedded in commit messages or code changes.
- Capability inventory: The skill can execute shell commands, perform git operations (
commit,push,merge), and interact with GitHub via theghtool (SKILL.md Steps 2, 3, 3.25, 6, 7, 8). - Sanitization: No sanitization or validation of the ingested strings is performed before they are used to generate Pull Request content or influence versioning logic.
Audit Metadata