classify-github-flakes

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a manifest and API specification from external domains (cristianmoroaica.github.io and mimirslab.workers.dev) to resolve service endpoints.
  • [DATA_EXFILTRATION]: Sends a public GitHub Actions run URL to a remote worker-based API. Security is maintained through explicit instructions forbidding the transmission of credentials, private-repository URLs, or sensitive environment data.
  • [PROMPT_INJECTION]: Employs explicit boundary instructions to mitigate indirect prompt injection, directing the agent to treat all data returned from GitHub or the API as untrusted content rather than instructions. It further enforces a strict schema for the retry decision field.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 01:39 PM
Security Audit — agent-trust-hub — classify-github-flakes