skills/withqwerty/ship/ship-think/Gen Agent Trust Hub

ship-think

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted data from the local directory and configuration files to formulate questions.
  • Ingestion points: Uses Read, Glob, and Grep to ingest content from the project codebase and the specific profile file .claude/ship.local.md.
  • Boundary markers: The instructions do not define explicit delimiters or instructions to the agent to disregard embedded directives within the ingested files.
  • Capability inventory: Capabilities are restricted to file system reading (Read, Glob, Grep) and posing questions to the user (AskUserQuestion). There are no tools for network exfiltration or code execution.
  • Sanitization: There is no mention of input validation or content sanitization for the data read from the codebase before it is used to generate the question cascade.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:41 AM
Security Audit — agent-trust-hub — ship-think