github-explorer

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from multiple external sources, which presents a surface for indirect prompt injection attacks where malicious instructions could be embedded in the fetched content.
  • Ingestion points: Content is retrieved from GitHub (README, Issues, Commits) and external community sites (e.g., V2EX, Reddit, WeChat, technical blogs) via web_fetch, content-extract, and API calls.
  • Boundary markers: There are no instructions provided to use specific delimiters or protective prompts to help the model differentiate between its analysis logic and the data it is processing.
  • Capability inventory: The skill utilizes local shell execution capabilities (python3) and network access (curl) to perform its analysis.
  • Sanitization: The workflow does not specify any sanitization, filtering, or validation steps for the content fetched from the web before it is analyzed by the agent.
  • [COMMAND_EXECUTION]: The skill invokes local shell commands to perform its core search and extraction functions.
  • Evidence: The instructions direct the agent to execute python3 skills/search-layer/scripts/search.py and python3 skills/content-extract/scripts/content_extract.py with various arguments.
  • Context: These are internal dependencies within the agent's skill environment. While not inherently malicious, they represent the execution surface used by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 01:43 PM