opensource-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes local project files which could potentially contain adversarial instructions intended to influence the subagents' behavior.
  • Ingestion points: Local source files located at the user-defined {SOURCE_PATH}.
  • Boundary markers: The subagent prompts for forking, sanitization, and packaging do not currently employ explicit delimiters to separate untrusted file content from the agent's instructions.
  • Capability inventory: The skill has access to file system operations, subagent orchestration, and repository management via the GitHub CLI.
  • Sanitization: No pre-processing or escaping of the ingested code is performed before it is passed to the LLM context.
  • [COMMAND_EXECUTION]: The skill utilizes standard shell utilities and the GitHub CLI to manage the open-source pipeline.
  • It uses mkdir to prepare staging environments and ls/cat to provide status updates to the user.
  • It interacts with the GitHub API and creates public repositories using the gh command-line tool, which requires explicit user confirmation before execution.
  • [DYNAMIC_EXECUTION]: The workflow includes the generation of a setup.sh script intended for project bootstrapping.
  • The opensource-packager agent generates the script content and is instructed to ensure it is executable.
  • This script is created for the convenience of the project's future users and is not automatically executed by the agent during the preparation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — opensource-pipeline