skills/withqwerty/ship/ship-focus/Gen Agent Trust Hub

ship-focus

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute git commands, specifically git diff, git diff --stat, and git status. These operations are used to examine local workspace changes and are consistent with the skill's stated purpose of scope management.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources that could potentially contain malicious instructions.
  • Ingestion points: The skill reads the output of git diff (code changes) and the contents of the .claude/ship.local.md configuration file.
  • Boundary markers: The instructions do not specify explicit delimiters or boundary markers to isolate the content of the files from the agent's core instructions.
  • Capability inventory: The skill has access to Bash, Read, Glob, Grep, and AskUserQuestion tools.
  • Sanitization: There is no mention of sanitizing or escaping the content retrieved from the files or command outputs before processing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:41 AM
Security Audit — agent-trust-hub — ship-focus