airflow-publish-changes

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows established open-source contribution workflows and does not contain any malicious instructions, obfuscation, or persistence mechanisms. All operations are transparent and consistent with the stated purpose.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard CLI tools (git, gh) for repository management tasks such as renaming remotes, fetching updates, rebasing branches, and creating pull requests. It also uses a project-specific utility, prek, to run pre-commit hooks and tests. These are routine development actions.
  • [EXTERNAL_DOWNLOADS]: Interactions are directed towards the official Apache Airflow GitHub repository (apache/airflow). As this belongs to a well-known and trusted organization, these references are considered safe.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect injection by reading external data like PR lists and git diffs.
  • Ingestion points: Data is ingested via gh pr list and git diff commands.
  • Boundary markers: Absent in the instructions, however, the skill mandates the use of the --web flag for PR creation, which ensures a human-in-the-loop review process on the GitHub website before any content is published.
  • Capability inventory: Capabilities are limited to git, gh, and prek operations.
  • Sanitization: No specific sanitization of the ingested data is described.
  • Severity: Low.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:24 AM
Security Audit — agent-trust-hub — airflow-publish-changes