ship-workflow-land
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources including pull request metadata and server responses.
- Ingestion points: Pull request titles, bodies, and status metadata are ingested via
gh pr view, and external server responses are retrieved viacurlhealth checks inSKILL.md. - Boundary markers: The instructions do not define explicit delimiters or use 'ignore embedded instructions' warnings when the agent interpolates this external content into deployment reports.
- Capability inventory: The skill possesses extensive capabilities including repository modification through
gh pr mergeandgit push, infrastructure management viaflyandkubectl, and network access viacurl. - Sanitization: There is no requirement for the agent to sanitize or validate external content before it is recorded in the permanent deployment record
07-deploy-report.md.
Audit Metadata