github-project-contributor-finder-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub that could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Data including repository_description and contributor bio is retrieved from GitHub via the BrowserAct API in scripts/github_project_contributor_finder_api.py and returned to the agent's context.
  • Boundary markers: The skill instructions do not specify the use of delimiters or provide warnings to the agent to disregard instructions embedded within the fetched data.
  • Capability inventory: The agent is expected to execute Python scripts, monitor terminal output, and interact with the user, creating a surface where injected instructions could trigger unwanted actions.
  • Sanitization: There is no evidence of sanitization, filtering, or escaping of the external GitHub content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — github-project-contributor-finder-api-skill