route-github-agent-checks

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves a central manifest and specific operational sub-skills from the author's public repository site at cristianmoroaica.github.io.
  • [REMOTE_CODE_EXECUTION]: Directs the agent to dynamically load and follow additional instructions from remote URLs (SKILL.md files) at runtime, which is used to execute specialized sub-tasks.
  • [DATA_EXFILTRATION]: Facilitates network operations to an external decision API (bountyverdict-agent-production.mimirslab.workers.dev) and coordinates blockchain payment challenges for paid decision services.
  • [PROMPT_INJECTION]: Identifies an indirect prompt injection surface through the processing of untrusted GitHub content (issues, PRs, and third-party skills) and explicitly mitigates this by instructing the agent to treat such data strictly as evidence and not as commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 01:50 PM
Security Audit — agent-trust-hub — route-github-agent-checks