ship
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a
/shipcommand that executes shell operations using standard tools likegitand the GitHub CLI (gh). These operations include viewing status, diffing, staging, committing, pushing, and updating issues. This functionality is the primary purpose of the skill and aligns with normal developer workflows.\n- [PERSISTENCE_MECHANISMS]: The skill instructions facilitate persistence by guiding the user to copy the command definition file into the~/.claude/commands/directory. This ensures the slash command remains available across Claude Code sessions, which is the platform's standard method for command persistence.\n- [INDIRECT_PROMPT_INJECTION]: The/shipcommand ingests user input through the$ARGUMENTSvariable and incorporates it into shell commands such asgh issue comment <number>. This interpolation creates a surface for indirect prompt injection.\n - Ingestion points: The
$ARGUMENTSvariable incommands/ship.mdaccepts arbitrary user-supplied strings.\n - Boundary markers: No explicit delimiters or safety wrappers are used to isolate the argument content from the rest of the prompt logic.\n
- Capability inventory: The skill has the capability to execute shell commands, specifically
gitandgh.\n - Sanitization: The prompt instructs the agent to check if the input "looks like" an issue number or URL, but no robust technical validation or escaping is applied to the input before execution.
Audit Metadata