opensource-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local project files that could contain malicious instructions designed to influence the behavior of the sanitizer or packager sub-agents.
- Ingestion points: Arbitrary project files are read from
SOURCE_PATHas described in the protocols for theopensource-forker,opensource-sanitizer, andopensource-packageragents inSKILL.md. - Boundary markers: The skill does not explicitly use delimiters or "ignore instructions" warnings when passing project content to sub-agents.
- Capability inventory: The skill possesses the ability to read and write files, execute shell commands, and create public GitHub repositories using the
ghCLI. - Sanitization: The workflow includes a mandatory
opensource-sanitizersub-agent designed to audit for secrets, PII, and dangerous files, providing a specific defensive layer against accidental data exposure. - [COMMAND_EXECUTION]: The skill utilizes shell commands to manage a local staging environment and interact with GitHub's CLI tool.
- Evidence: The protocol in
SKILL.mdusesmkdir -pto create staging areas,lsandcatto manage staging status, andgh repo createto publish the final project to GitHub. - [DYNAMIC_EXECUTION]: The skill generates and prepares executable scripts for the final project package.
- Evidence: In Step 5 of the protocol in
SKILL.md, theopensource-packageragent is instructed to generate asetup.shbootstrap script and ensure it is marked as executable.
Audit Metadata