security-awareness-malicious-repository-detection

Pass

Audited by Gen Agent Trust Hub on May 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and analyze data from external GitHub repositories, which are untrusted third-party sources.
  • Ingestion points: Repository metadata such as descriptions, topics, and metrics fetched from the GitHub API or provided via user triggers.
  • Boundary markers: The instructions do not define boundary markers (e.g., delimiters) to separate the analysis logic from the untrusted content of the repositories being analyzed.
  • Capability inventory: The skill includes logic for fetching repository data, performing heuristic risk assessment, and reporting repositories to external abuse endpoints.
  • Sanitization: The analysis logic uses basic string matching and regex which may be insufficient to prevent adversarial content within a repository description from influencing the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 29, 2026, 05:00 AM
Security Audit — agent-trust-hub — security-awareness-malicious-repository-detection