publish-project-to-github
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill coordinates several local command-line operations to manage the project lifecycle. It utilizes
gitfor version control management, the GitHub CLI (gh) for repository creation and API-based configuration, andpython3to host a local server for pre-deployment testing. Additionally, it executes a bundled shell script,audit_public_project.sh, which usesripgrepto scan the project for sensitive data. - [DATA_EXFILTRATION]: Although the skill is designed to upload data to a remote service, it incorporates significant security controls to ensure only intended public data is shared. It mandates a pre-push audit that specifically searches for and blocks common secret patterns (e.g., OpenAI keys, AWS keys, GitHub tokens) and sensitive files like
.envor private keys. The instructions also strictly prohibit changing repository visibility or force-pushing without explicit user authorization. - [PROMPT_INJECTION]: The skill is subject to an indirect prompt injection attack surface because it reads and processes untrusted local project files to generate documentation and project summaries.
- Ingestion points: The agent reads the directory structure and the content of files such as
index.htmlandpackage.jsonto extract project details. - Boundary markers: While it uses a structured
README-template.md, it does not employ specific delimiters to isolate interpolated project data from the instruction context. - Capability inventory: The skill possesses the ability to execute shell scripts, perform file writes via Git, and initiate network requests through the GitHub CLI.
- Sanitization: The
audit_public_project.shscript acts as a primary filter to detect and prevent the processing of high-risk sensitive files, and the instructions require the agent to manually verify findings before proceeding.
Audit Metadata