github-hub
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external repository and organization data, exposing an attack surface where untrusted content could influence agent behavior.
- Ingestion points: Captures user input and fetches dynamic repository, organization, and team metadata via
#tool:mcp_github_github_get_meand#tool:mcp_github_github_get_teamsinSKILL.md. - Boundary markers: Absent; there are no explicit delimiters or strict isolation instructions defined to prevent the agent from obeying instructions embedded in the external metadata.
- Capability inventory: Orchestrates context and delegates actions to sub-agents (e.g.,
@repo-admin,@team-manager,@pr-review) as outlined inSKILL.md. - Sanitization: Absent; the instructions do not specify any validation or sanitization routines for the data fetched via the MCP tools before passing it to sub-agents.
Audit Metadata