git
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection (LOW): The skill ingests untrusted data from external sources (PR comments and commit messages) which could contain malicious instructions intended to manipulate the agent's behavior.\n
- Ingestion points: External data is read in
references/pr-review-workflow.md(viagh pr view --comments) andreferences/worktree-summary.md(viagit log).\n - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when processing this external content.\n
- Capability inventory: The skill has state-changing capabilities across multiple files, including
git push,git commit,gh pr create, andgit worktree remove.\n - Sanitization: No explicit sanitization of the ingested text is performed.\n
- Mitigation: The skill implements a robust 'Confirmation Policy' in
SKILL.mdthat requires human approval for all state-changing or irreversible actions, providing a strong defense against automated exploitation of injection vulnerabilities.
Audit Metadata