github-repokit-gcp-wif

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill performs legitimate infrastructure management tasks.
  • [EXTERNAL_DOWNLOADS]: Fetches a Terraform module from the author's repository at github.com/emrecavunt/github-repokit. This is a standard vendor-provided dependency for this skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a small attack surface as it accepts user input for GCP project IDs and GitHub repository names. However, the risk is mitigated by the instruction for the agent to stop before applying changes, requiring human verification.
  • Ingestion points: User-provided values for project ID and repository names in SKILL.md and terragrunt.hcl.
  • Boundary markers: Placeholders like <GCP_PROJECT_ID> are used.
  • Capability inventory: File creation (root.hcl generate blocks) and shell command execution (Makefile targets calling terragrunt).
  • Sanitization: None explicitly defined for raw strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 08:33 PM
Security Audit — agent-trust-hub — github-repokit-gcp-wif