security-dashboard
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI tool (
gh) to interact with GitHub's REST API. This involves executing shell commands to fetch user information (gh api user) and manage security alerts, including listing, detailing, and dismissing alerts via API requests.\n- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content from GitHub security alerts (Dependabot, Code Scanning, and Secret Scanning). This data, which includes rule descriptions and vulnerability details, is not fully controlled by the skill and could potentially contain malicious instructions. However, the risk is inherent to the skill's primary function of triaging external security data.\n - Ingestion points: External data ingested via GitHub REST API calls for various security alert types (Dependabot, Code Scanning, Secret Scanning).\n
- Boundary markers: No explicit delimiters or instructions to ignore embedded prompts were found in the skill definition to isolate alert content.\n
- Capability inventory: The skill has the capability to execute API commands that modify alert states and write structured security reports to the local workspace.\n
- Sanitization: No specific mechanisms for sanitizing or escaping the alert content before processing were identified in the workflow.
Audit Metadata