github-workflow-automation
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: A command injection vulnerability exists in the AI Mention Bot workflow (Section 5.1). The script uses
${{ github.event.comment.body }}directly inside a shell command:question=$(echo "${{ github.event.comment.body }}" | sed 's/.*@ai-helper//'). Because GitHub Actions expands this expression before execution, a malicious comment containing shell metacharacters (e.g., backticks or semicolons) can execute arbitrary code on the runner. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data into LLM prompts across multiple features without using boundary markers or sanitization.
- Ingestion points:
SKILL.md(Sections 1.1 - PR diffs, 2.1
- Issue body/title, 3.2
- Commit messages, 5.1
- Comments).
- Boundary markers: Absent in all prompt templates; untrusted content is directly concatenated.
- Capability inventory: The AI can write PR reviews, add/remove labels, create comments, and fail CI/CD builds.
- Sanitization: None detected. A malicious PR or issue could contain instructions to bypass review logic or mislabel critical items.
- [DYNAMIC_EXECUTION]: The 'Smart Cherry-Pick' implementation (Section 4.2) suggests a pattern for AI-assisted conflict resolution where an AI's output is directly applied to files:
const resolution = await ai.resolveConflict(conflict); await applyResolution(conflict.file, resolution);. Executing AI-generated code fixes without human-in-the-loop validation is a high-risk dynamic execution pattern. - [EXTERNAL_DOWNLOADS]: The skill references and downloads configurations from the Gemini CLI repository and official GitHub Actions repositories, which are recognized as well-known and trusted sources.
Audit Metadata