make-ci-green
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes Jenkins console output, which is an external data source that could contain malicious instructions.
- Ingestion points:
retrigger-ci.pyfetches build logs from Jenkins via thefetch_console_tailfunction. - Boundary markers: The instructions do not define clear boundaries or provide explicit warnings to the agent when presenting parsed log data.
- Capability inventory: The skill has the ability to execute shell commands (
gh,git) and perform authenticated network operations (triggering Jenkins builds). - Sanitization: No sanitization is performed on the log content before it is parsed for test failure markers or displayed to the agent.
- [COMMAND_EXECUTION]: The script executes local command-line tools to interact with GitHub and the repository.
- Evidence:
retrigger-ci.pyusessubprocess.runto call theghCLI,git grep, and a local analysis scriptcheck-upstream-flake.py. - Mitigation: The script uses list-based arguments instead of shell strings and validates input parameters, such as casting the PR number to an integer, which are established safe practices for process execution.
Audit Metadata