dev-git-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill integrates numerous standard development tools and packages such as release-it, husky, commitlint, and various well-known GitHub Actions for CI/CD pipelines (e.g., in assets/ci-cd/github-pr-checks.yml). These dependencies are from well-known vendors and are necessary for the skill's stated purpose of managing Git workflows.
- [COMMAND_EXECUTION]: To automate Git workflows, the skill executes various shell commands for branch management, dependency installation (npm, pip), and testing (pytest, vitest). This command execution is a core part of the skill's functionality and occurs in well-defined contexts such as worktree setup and CI/CD gates.
- [DYNAMIC_EXECUTION]: The skill facilitates the use of Git hooks (Husky, Lefthook) and repository-local automation scripts (e.g., agents-skills-feedback-loop/scripts/append_learning.py) to streamline repetitive developer tasks. These mechanisms allow for runtime execution of scripts based on repository events.
- [INDIRECT_PROMPT_INJECTION]: The skill operates on repository data, including pull request descriptions and commit messages, which could potentially contain adversarial instructions. This constitutes a standard vulnerability surface for agents with repository write and command execution capabilities, although the risk is mitigated by the skill's focus on structured workflows.
Audit Metadata