oneshot-workflow

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill's operations are restricted to standard version control actions and workflow state management through a specialized MCP server.
  • [COMMAND_EXECUTION]: The skill uses standard Git commands (e.g., git push) for its primary purpose of synchronizing code changes with a remote repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill monitors user conversation for specific triggers to influence workflow state transitions (e.g., escalating from a direct commit to a PR). While this involves ingesting external conversational data, it is a standard design choice for the skill's interaction model and is executed through specific state-management tools.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 04:36 AM