opensource-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local project files that could contain malicious instructions designed to influence the behavior of the sanitizer or packager sub-agents.
  • Ingestion points: Arbitrary project files are read from SOURCE_PATH as described in the protocols for the opensource-forker, opensource-sanitizer, and opensource-packager agents in SKILL.md.
  • Boundary markers: The skill does not explicitly use delimiters or "ignore instructions" warnings when passing project content to sub-agents.
  • Capability inventory: The skill possesses the ability to read and write files, execute shell commands, and create public GitHub repositories using the gh CLI.
  • Sanitization: The workflow includes a mandatory opensource-sanitizer sub-agent designed to audit for secrets, PII, and dangerous files, providing a specific defensive layer against accidental data exposure.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage a local staging environment and interact with GitHub's CLI tool.
  • Evidence: The protocol in SKILL.md uses mkdir -p to create staging areas, ls and cat to manage staging status, and gh repo create to publish the final project to GitHub.
  • [DYNAMIC_EXECUTION]: The skill generates and prepares executable scripts for the final project package.
  • Evidence: In Step 5 of the protocol in SKILL.md, the opensource-packager agent is instructed to generate a setup.sh bootstrap script and ensure it is marked as executable.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — opensource-pipeline