ship-think
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted data from the local directory and configuration files to formulate questions.
- Ingestion points: Uses
Read,Glob, andGrepto ingest content from the project codebase and the specific profile file.claude/ship.local.md. - Boundary markers: The instructions do not define explicit delimiters or instructions to the agent to disregard embedded directives within the ingested files.
- Capability inventory: Capabilities are restricted to file system reading (
Read,Glob,Grep) and posing questions to the user (AskUserQuestion). There are no tools for network exfiltration or code execution. - Sanitization: There is no mention of input validation or content sanitization for the data read from the codebase before it is used to generate the question cascade.
Audit Metadata