skills/decisionnerd/dev-skills/repos/Gen Agent Trust Hub

repos

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external repositories during audit and inventory operations, specifically reading repository metadata, workflow definitions, triggers, and topics (documented in SKILL.md under status/audit and references/ci.md under status). These ingestion points lack explicit boundary markers or sanitization before interpolation into the agent context. Given the skill capabilities for repository mutation (settings, transfer, archive) and configuration of secrets via Pulumi ESC, this creates a vulnerability surface where malicious content in an audited repository could influence the agent actions.
  • [SAFE]: The skill implements and encourages secure secrets management by defaulting to Pulumi ESC with OIDC (GitHub id-token: write), which significantly reduces the risk associated with long-lived static cloud credentials in CI/CD environments.
  • [SAFE]: The repository management and CI hardening instructions prioritize supply chain security by recommending the pinning of third-party actions to specific commit SHAs and enforcing least-privilege permission blocks within workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — repos