github-workflow-automation
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The mention-bot.yml workflow (Section 5.1) is vulnerable to command injection. The Extract question step uses the GitHub Actions expression ${{ github.event.comment.body }} directly within a shell command: question=$(echo "${{ github.event.comment.body }}" | sed ...). An attacker can include shell metacharacters like ; or $() in a comment to execute arbitrary code on the runner environment.
- [COMMAND_EXECUTION]: The auto-rebase.yml workflow (Section 4.1) allows unauthorized users to trigger sensitive Git operations. The workflow triggers on any issue comment containing /rebase without verifying that the commenter has write access to the repository, potentially allowing an attacker to force a rebase and force-push on pull request branches.
- [PROMPT_INJECTION]: The skill exhibits multiple surfaces for indirect prompt injection (Category 8) across various workflows. Ingestion points: PR diffs (ai-review.yml), issue content (issue-triage.yml), commit logs (deploy.yml), and user comments (mention-bot.yml). Boundary markers: Absent. Capability inventory: Writing PR reviews, labeling issues, and influencing deployment status. Sanitization: None. This allows attackers to craft content that tricks the AI into performing unintended actions.
- [SAFE]: Credentials and API keys are managed via GitHub Secrets rather than being hardcoded in scripts or workflows.
- [SAFE]: All referenced GitHub Actions and NPM packages are from trusted and well-known sources.
Recommendations
- AI detected serious security threats
Audit Metadata