contributions-hub
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns such as obfuscation, exfiltration, or persistence mechanisms were found.
- [COMMAND_EXECUTION]: The skill leverages GitHub MCP tools to perform community management tasks. All actions that modify repository state are protected by mandatory user preview and confirmation steps.
- [PROMPT_INJECTION]: The skill processes untrusted external data (GitHub Discussion comments), which creates an indirect prompt injection surface. However, the risk is mitigated by the instruction to never auto-post and to always require manual approval of generated content.
Audit Metadata