ship-init
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data to generate a 'Current reality' summary, creating a minor surface for indirect injection from the codebase content.
- Ingestion points: The instructions direct the agent to read the project structure, README, recent commits, and existing configuration files (SKILL.md).
- Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands during the interpolation of project data into the final profile.
- Capability inventory: The skill utilizes
Read,Write,Glob, andBashtools to perform project inspection and store configuration. - Sanitization: No specific filtering or validation of the ingested codebase text is defined before it is formatted into the profile.
Audit Metadata