github-pr-proof-assets

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes appropriate use of developer tools (gh, curl, ffmpeg, ffprobe, jq) to verify repository context and process media files. It properly handles shell variables by using jq for URL encoding, which mitigates the risk of command injection through malformed filenames.
  • [DATA_EXFILTRATION]: Network operations are restricted to well-known GitHub domains (github.com and uploads.github.com). The skill includes explicit security warnings to prevent the exposure or storage of the GitHub authentication token in logs or configuration files, ensuring it is only expanded in-memory during specific requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with local files and external API responses.
  • Ingestion points: Local media assets and response bodies from GitHub API calls referenced in SKILL.md.
  • Boundary markers: While there are no specific prompt delimiters for the data content, the instructions mandate a manual review of the final comment body-file before execution of the gh comment command.
  • Capability inventory: The skill uses curl and gh for network communication and ffmpeg for file processing and writing.
  • Sanitization: The skill employs jq to sanitize and encode external data strings before they are interpolated into shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — github-pr-proof-assets