skills/catena-labs/dev-skills/babysit/Gen Agent Trust Hub

babysit

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a PR health-check loop using local scripts (scan.sh, mark-seen.sh) and the GitHub CLI to monitor branch status. While the skill processes external data like PR comments and CI logs—which constitutes an indirect prompt injection surface—it manages this risk through keyword filtering, log truncation, and 'stop-and-ask' triggers for sensitive operations. No malicious patterns such as credential exfiltration, obfuscation, or unauthorized remote code execution were detected. Use of the gh CLI is limited to official GitHub API interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 07:22 PM
Security Audit — agent-trust-hub — babysit