skills/brave/brave-core/make-ci-green/Gen Agent Trust Hub

make-ci-green

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes Jenkins console output, which is an external data source that could contain malicious instructions.
  • Ingestion points: retrigger-ci.py fetches build logs from Jenkins via the fetch_console_tail function.
  • Boundary markers: The instructions do not define clear boundaries or provide explicit warnings to the agent when presenting parsed log data.
  • Capability inventory: The skill has the ability to execute shell commands (gh, git) and perform authenticated network operations (triggering Jenkins builds).
  • Sanitization: No sanitization is performed on the log content before it is parsed for test failure markers or displayed to the agent.
  • [COMMAND_EXECUTION]: The script executes local command-line tools to interact with GitHub and the repository.
  • Evidence: retrigger-ci.py uses subprocess.run to call the gh CLI, git grep, and a local analysis script check-upstream-flake.py.
  • Mitigation: The script uses list-based arguments instead of shell strings and validates input parameters, such as casting the PR number to an integer, which are established safe practices for process execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 05:47 PM
Security Audit — agent-trust-hub — make-ci-green