github-workflow-automation

Fail

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The mention-bot.yml workflow (Section 5.1) is vulnerable to command injection. The Extract question step uses the GitHub Actions expression ${{ github.event.comment.body }} directly within a shell command: question=$(echo "${{ github.event.comment.body }}" | sed ...). An attacker can include shell metacharacters like ; or $() in a comment to execute arbitrary code on the runner environment.
  • [COMMAND_EXECUTION]: The auto-rebase.yml workflow (Section 4.1) allows unauthorized users to trigger sensitive Git operations. The workflow triggers on any issue comment containing /rebase without verifying that the commenter has write access to the repository, potentially allowing an attacker to force a rebase and force-push on pull request branches.
  • [PROMPT_INJECTION]: The skill exhibits multiple surfaces for indirect prompt injection (Category 8) across various workflows. Ingestion points: PR diffs (ai-review.yml), issue content (issue-triage.yml), commit logs (deploy.yml), and user comments (mention-bot.yml). Boundary markers: Absent. Capability inventory: Writing PR reviews, labeling issues, and influencing deployment status. Sanitization: None. This allows attackers to craft content that tricks the AI into performing unintended actions.
  • [SAFE]: Credentials and API keys are managed via GitHub Secrets rather than being hardcoded in scripts or workflows.
  • [SAFE]: All referenced GitHub Actions and NPM packages are from trusted and well-known sources.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — github-workflow-automation