github-project-contributor-finder-api-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub that could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Data including
repository_descriptionand contributorbiois retrieved from GitHub via the BrowserAct API inscripts/github_project_contributor_finder_api.pyand returned to the agent's context. - Boundary markers: The skill instructions do not specify the use of delimiters or provide warnings to the agent to disregard instructions embedded within the fetched data.
- Capability inventory: The agent is expected to execute Python scripts, monitor terminal output, and interact with the user, creating a surface where injected instructions could trigger unwanted actions.
- Sanitization: There is no evidence of sanitization, filtering, or escaping of the external GitHub content before it is processed by the agent.
Audit Metadata