Back to skill

Security audit

stack-push

Security checks for vulnerabilities and agentic risk

Overview

This skill is an instruction-only workflow for pushing stacked git branches and opening draft GitHub PRs, with no hidden execution or unrelated data access found.

Install only if you want an agent-assisted workflow that can push stack branches and create GitHub PRs in the current repository. Review the branch prefix, base branch, and generated PR text before allowing the commands to run.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:123