github-hub

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external repository and organization data, exposing an attack surface where untrusted content could influence agent behavior.
  • Ingestion points: Captures user input and fetches dynamic repository, organization, and team metadata via #tool:mcp_github_github_get_me and #tool:mcp_github_github_get_teams in SKILL.md.
  • Boundary markers: Absent; there are no explicit delimiters or strict isolation instructions defined to prevent the agent from obeying instructions embedded in the external metadata.
  • Capability inventory: Orchestrates context and delegates actions to sub-agents (e.g., @repo-admin, @team-manager, @pr-review) as outlined in SKILL.md.
  • Sanitization: Absent; the instructions do not specify any validation or sanitization routines for the data fetched via the MCP tools before passing it to sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 05:59 AM