github-explorer
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from multiple external sources, which presents a surface for indirect prompt injection attacks where malicious instructions could be embedded in the fetched content.
- Ingestion points: Content is retrieved from GitHub (README, Issues, Commits) and external community sites (e.g., V2EX, Reddit, WeChat, technical blogs) via
web_fetch,content-extract, and API calls. - Boundary markers: There are no instructions provided to use specific delimiters or protective prompts to help the model differentiate between its analysis logic and the data it is processing.
- Capability inventory: The skill utilizes local shell execution capabilities (
python3) and network access (curl) to perform its analysis. - Sanitization: The workflow does not specify any sanitization, filtering, or validation steps for the content fetched from the web before it is analyzed by the agent.
- [COMMAND_EXECUTION]: The skill invokes local shell commands to perform its core search and extraction functions.
- Evidence: The instructions direct the agent to execute
python3 skills/search-layer/scripts/search.pyandpython3 skills/content-extract/scripts/content_extract.pywith various arguments. - Context: These are internal dependencies within the agent's skill environment. While not inherently malicious, they represent the execution surface used by the skill.
Audit Metadata