diagnose-github-actions
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a dynamic configuration manifest from a vendor-controlled GitHub Pages site at
https://cristianmoroaica.github.io/bountyverdict/agent-manifest.jsonto identify the production API endpoint. - [DATA_EXFILTRATION]: The skill involves network operations to a remote API, but it incorporates explicit safeguards instructing the agent never to reveal sensitive information such as wallet secrets, seed phrases, or private keys.
- [PROMPT_INJECTION]: The instructions include a specific mitigation strategy for indirect prompt injection, requiring the agent to treat all log data retrieved from the external service as untrusted evidence rather than executable instructions.
Audit Metadata