dev-git-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill integrates numerous standard development tools and packages such as release-it, husky, commitlint, and various well-known GitHub Actions for CI/CD pipelines (e.g., in assets/ci-cd/github-pr-checks.yml). These dependencies are from well-known vendors and are necessary for the skill's stated purpose of managing Git workflows.
  • [COMMAND_EXECUTION]: To automate Git workflows, the skill executes various shell commands for branch management, dependency installation (npm, pip), and testing (pytest, vitest). This command execution is a core part of the skill's functionality and occurs in well-defined contexts such as worktree setup and CI/CD gates.
  • [DYNAMIC_EXECUTION]: The skill facilitates the use of Git hooks (Husky, Lefthook) and repository-local automation scripts (e.g., agents-skills-feedback-loop/scripts/append_learning.py) to streamline repetitive developer tasks. These mechanisms allow for runtime execution of scripts based on repository events.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on repository data, including pull request descriptions and commit messages, which could potentially contain adversarial instructions. This constitutes a standard vulnerability surface for agents with repository write and command execution capabilities, although the risk is mitigated by the skill's focus on structured workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — dev-git-workflow