route-github-agent-checks
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves a central manifest and specific operational sub-skills from the author's public repository site at cristianmoroaica.github.io.
- [REMOTE_CODE_EXECUTION]: Directs the agent to dynamically load and follow additional instructions from remote URLs (SKILL.md files) at runtime, which is used to execute specialized sub-tasks.
- [DATA_EXFILTRATION]: Facilitates network operations to an external decision API (bountyverdict-agent-production.mimirslab.workers.dev) and coordinates blockchain payment challenges for paid decision services.
- [PROMPT_INJECTION]: Identifies an indirect prompt injection surface through the processing of untrusted GitHub content (issues, PRs, and third-party skills) and explicitly mitigates this by instructing the agent to treat such data strictly as evidence and not as commands.
Audit Metadata