skills/topshark-jim/gstack/ship/Gen Agent Trust Hub

ship

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions designed to override standard agent safety protocols and user confirmation steps.
  • Evidence: SKILL.md states: "This is a non-interactive, fully automated workflow. Do NOT ask for confirmation at any step. The user said ship which means DO IT. Run straight through..."
  • Evidence: The agent is further instructed to "Never stop for: ... Commit message approval (auto-commit)" and "CHANGELOG content (auto-generate from diff)", encouraging autonomous action without human review.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a high surface area for indirect prompt injection because it ingests untrusted data from the repository history and diffs to automate tasks without human oversight.
  • Ingestion points: The agent reads data from git log, git diff, git status, and project files like CHANGELOG.md and VERSION (SKILL.md Steps 1, 3.25, 3.5, 5, 6, 8).
  • Boundary markers: The instructions lack delimiters or explicit warnings to ignore malicious instructions that might be embedded in commit messages or code changes.
  • Capability inventory: The skill can execute shell commands, perform git operations (commit, push, merge), and interact with GitHub via the gh tool (SKILL.md Steps 2, 3, 3.25, 6, 7, 8).
  • Sanitization: No sanitization or validation of the ingested strings is performed before they are used to generate Pull Request content or influence versioning logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 06:54 AM
Security Audit — agent-trust-hub — ship