github-ops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
- Ingestion points: The skill retrieves and processes external content (titles, bodies, and comments) from GitHub issues and pull requests using
gh issue list,gh pr view, andgh run view --log-failedas described in the 'Issue Triage', 'PR Management', and 'CI/CD Operations' sections of SKILL.md. - Boundary markers: Absent. The skill provides no instructions to treat the retrieved GitHub content as untrusted or to use specific delimiters to isolate it from the agent's core instructions.
- Capability inventory: The skill possesses significant capabilities including modifying issues (
gh issue edit), posting comments (gh issue comment), re-running workflows (gh run rerun), and creating releases (gh release create) as defined throughout SKILL.md. - Sanitization: Absent. There are no instructions or patterns for sanitizing, validating, or filtering the content retrieved from the GitHub API before it is processed by the agent.
Audit Metadata