github-triage
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a local Python helper script (
scripts/gh_fetch.py) and the GitHub CLI (gh) to retrieve repository data. These operations are essential for the skill's purpose and are conducted through standard system tools.\n- [DATA_EXFILTRATION]: The skill accesses repository information, including code and issue content. All processed data remains within the local environment, and analysis results are stored in the temporary system directory (/tmp/). There is no evidence of data being transmitted to external servers.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from GitHub (issue and PR descriptions/comments) to generate analysis prompts for subagents. \n - Ingestion points: GitHub issue/PR body and comments (found in Phase 1 fetching logic and subagent prompt templates).\n
- Boundary markers: Absent. The subagent prompts do not contain specific delimiters or warnings to ignore instructions embedded in the issue content.\n
- Capability inventory: Subagents have access to file read tools, git history, and GitHub read-only API calls (found in Subagent Prompts section).\n
- Sanitization: None. The skill relies on subagent prompt constraints and a 'Zero-Action Policy' to prevent misuse.
Audit Metadata