diagnose-github-actions

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a dynamic configuration manifest from a vendor-controlled GitHub Pages site at https://cristianmoroaica.github.io/bountyverdict/agent-manifest.json to identify the production API endpoint.
  • [DATA_EXFILTRATION]: The skill involves network operations to a remote API, but it incorporates explicit safeguards instructing the agent never to reveal sensitive information such as wallet secrets, seed phrases, or private keys.
  • [PROMPT_INJECTION]: The instructions include a specific mitigation strategy for indirect prompt injection, requiring the agent to treat all log data retrieved from the external service as untrusted evidence rather than executable instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 01:39 PM
Security Audit — agent-trust-hub — diagnose-github-actions