github-triage

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local Python helper script (scripts/gh_fetch.py) and the GitHub CLI (gh) to retrieve repository data. These operations are essential for the skill's purpose and are conducted through standard system tools.\n- [DATA_EXFILTRATION]: The skill accesses repository information, including code and issue content. All processed data remains within the local environment, and analysis results are stored in the temporary system directory (/tmp/). There is no evidence of data being transmitted to external servers.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from GitHub (issue and PR descriptions/comments) to generate analysis prompts for subagents. \n
  • Ingestion points: GitHub issue/PR body and comments (found in Phase 1 fetching logic and subagent prompt templates).\n
  • Boundary markers: Absent. The subagent prompts do not contain specific delimiters or warnings to ignore instructions embedded in the issue content.\n
  • Capability inventory: Subagents have access to file read tools, git history, and GitHub read-only API calls (found in Subagent Prompts section).\n
  • Sanitization: None. The skill relies on subagent prompt constraints and a 'Zero-Action Policy' to prevent misuse.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:59 AM
Security Audit — agent-trust-hub — github-triage