github-workflow-automation

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: A command injection vulnerability exists in the AI Mention Bot workflow (Section 5.1). The script uses ${{ github.event.comment.body }} directly inside a shell command: question=$(echo "${{ github.event.comment.body }}" | sed 's/.*@ai-helper//'). Because GitHub Actions expands this expression before execution, a malicious comment containing shell metacharacters (e.g., backticks or semicolons) can execute arbitrary code on the runner.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data into LLM prompts across multiple features without using boundary markers or sanitization.
  • Ingestion points: SKILL.md (Sections 1.1
  • PR diffs, 2.1
  • Issue body/title, 3.2
  • Commit messages, 5.1
  • Comments).
  • Boundary markers: Absent in all prompt templates; untrusted content is directly concatenated.
  • Capability inventory: The AI can write PR reviews, add/remove labels, create comments, and fail CI/CD builds.
  • Sanitization: None detected. A malicious PR or issue could contain instructions to bypass review logic or mislabel critical items.
  • [DYNAMIC_EXECUTION]: The 'Smart Cherry-Pick' implementation (Section 4.2) suggests a pattern for AI-assisted conflict resolution where an AI's output is directly applied to files: const resolution = await ai.resolveConflict(conflict); await applyResolution(conflict.file, resolution);. Executing AI-generated code fixes without human-in-the-loop validation is a high-risk dynamic execution pattern.
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads configurations from the Gemini CLI repository and official GitHub Actions repositories, which are recognized as well-known and trusted sources.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 02:33 PM
Security Audit — agent-trust-hub — github-workflow-automation