opensource-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes local project files which could potentially contain adversarial instructions intended to influence the subagents' behavior.
- Ingestion points: Local source files located at the user-defined
{SOURCE_PATH}. - Boundary markers: The subagent prompts for forking, sanitization, and packaging do not currently employ explicit delimiters to separate untrusted file content from the agent's instructions.
- Capability inventory: The skill has access to file system operations, subagent orchestration, and repository management via the GitHub CLI.
- Sanitization: No pre-processing or escaping of the ingested code is performed before it is passed to the LLM context.
- [COMMAND_EXECUTION]: The skill utilizes standard shell utilities and the GitHub CLI to manage the open-source pipeline.
- It uses
mkdirto prepare staging environments andls/catto provide status updates to the user. - It interacts with the GitHub API and creates public repositories using the
ghcommand-line tool, which requires explicit user confirmation before execution. - [DYNAMIC_EXECUTION]: The workflow includes the generation of a
setup.shscript intended for project bootstrapping. - The
opensource-packageragent generates the script content and is instructed to ensure it is executable. - This script is created for the convenience of the project's future users and is not automatically executed by the agent during the preparation process.
Audit Metadata