github-topics
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content that could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Fetches repository metadata and README summaries from the GitHub API in
src/github_fetcher.pyandsrc/readme_fetcher.py. - Boundary markers: The instructions do not define clear delimiters or warnings for the agent to ignore instructions embedded within the fetched GitHub data.
- Capability inventory: The skill has network access capabilities via the
requestslibrary to communicate with GitHub's API and raw content servers. - Sanitization: The
src/readme_fetcher.pyscript includes a markdown stripping utility (_extract_text_from_markdown) that removes code blocks, links, and styling, which serves as a mitigation against common injection techniques like hidden markdown commands.
Audit Metadata