github-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
  • Ingestion points: The skill retrieves and processes external content (titles, bodies, and comments) from GitHub issues and pull requests using gh issue list, gh pr view, and gh run view --log-failed as described in the 'Issue Triage', 'PR Management', and 'CI/CD Operations' sections of SKILL.md.
  • Boundary markers: Absent. The skill provides no instructions to treat the retrieved GitHub content as untrusted or to use specific delimiters to isolate it from the agent's core instructions.
  • Capability inventory: The skill possesses significant capabilities including modifying issues (gh issue edit), posting comments (gh issue comment), re-running workflows (gh run rerun), and creating releases (gh release create) as defined throughout SKILL.md.
  • Sanitization: Absent. There are no instructions or patterns for sanitizing, validating, or filtering the content retrieved from the GitHub API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — github-ops