setup-git-lite

Warn

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to override the agent's core instructions regarding Git integration, substituting built-in logic with a custom, restricted set of instructions.\n- [COMMAND_EXECUTION]: The skill modifies shell initialization files (e.g., .bashrc, .zshrc) to persistently export environment variables and alters global application configuration in ~/.claude/settings.json.\n- [COMMAND_EXECUTION]: The skill executes a local Node.js script to perform system-level modifications, which can involve risk if arguments are not properly sanitized by the underlying agent platform.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 26, 2026, 11:44 AM
Security Audit — agent-trust-hub — setup-git-lite