github-contributor
Pass
Audited by Gen Agent Trust Hub on Oct 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted external data, including project documentation (CONTRIBUTING.md), CI configurations, and automated bot reviews. This represents an inherent indirect prompt injection surface. However, the skill provides extensive mitigation instructions, emphasizing manual code review, the use of structured PR templates, and the rigorous filtering of external automated findings.
- Ingestion points: External repository metadata, contribution guidelines, and GitHub pull request comments.
- Boundary markers: Encourages the use of explicit summary and disclosure sections to separate human intent from AI-generated or externally sourced content.
- Capability inventory: Utilizes standard development tools (git, gh, pnpm, cargo, ruff) and testing utilities (sqlite3, python3).
- Sanitization: Instructions include a verification matrix and a 'ruthless filter' for external findings based on probability and cost.
- [DYNAMIC_EXECUTION]: The skill contains instructions for executing Python one-liners to process JSON data and using the Pillow library for image manipulation during testing.
- Evidence: Uses
python3 -cfor JSON formatting and PIL for cropping screenshots in isolated test environments (references/phase3_quality_gates_and_e2e.md). - [COMMAND_EXECUTION]: The skill provides a wide array of shell commands for git operations, GitHub CLI interactions, and project-specific build tools. These operations are restricted to the intended purpose of repository contribution and include explicit warnings regarding environment isolation and data protection.
- Evidence: Extensive use of
git,gh, and language-specific test runners across all reference files.
Audit Metadata