github
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub including pull request metadata and CI logs which could contain malicious instructions designed to influence the agent behavior. 1. Ingestion points: PR dashboard (references/pr-dashboard.md) and CI log viewer (references/ci-monitor.md). 2. Boundary markers: No specific delimiters or safety instructions are defined to separate untrusted data from agent instructions. 3. Capability inventory: The skill has the ability to merge PRs, set secrets, and perform state-changing API operations (SKILL.md). 4. Sanitization: The skill does not implement sanitization for external content before processing.
- [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of GitHub CLI extensions from arbitrary external repositories. 1. Source: Instructions in references/extensions.md allow installing from any OWNER/REPO. 2. Execution method: The command 'gh extension install' downloads and installs executable code. 3. Mitigation: The skill specifies that user confirmation is required for extension installation.
Audit Metadata