skills/yuen30/my-skills/ship/Gen Agent Trust Hub

ship

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a /ship command that executes shell operations using standard tools like git and the GitHub CLI (gh). These operations include viewing status, diffing, staging, committing, pushing, and updating issues. This functionality is the primary purpose of the skill and aligns with normal developer workflows.\n- [PERSISTENCE_MECHANISMS]: The skill instructions facilitate persistence by guiding the user to copy the command definition file into the ~/.claude/commands/ directory. This ensures the slash command remains available across Claude Code sessions, which is the platform's standard method for command persistence.\n- [INDIRECT_PROMPT_INJECTION]: The /ship command ingests user input through the $ARGUMENTS variable and incorporates it into shell commands such as gh issue comment <number>. This interpolation creates a surface for indirect prompt injection.\n
  • Ingestion points: The $ARGUMENTS variable in commands/ship.md accepts arbitrary user-supplied strings.\n
  • Boundary markers: No explicit delimiters or safety wrappers are used to isolate the argument content from the rest of the prompt logic.\n
  • Capability inventory: The skill has the capability to execute shell commands, specifically git and gh.\n
  • Sanitization: The prompt instructs the agent to check if the input "looks like" an issue number or URL, but no robust technical validation or escaping is applied to the input before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:13 AM
Security Audit — agent-trust-hub — ship