diagnose-workflow-failure

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill ingests untrusted GitHub Action logs and interprets them to recommend or apply automated fixes. A malicious actor could inject instructions into the CI/CD logs that deceive the agent into performing unauthorized file modifications or command executions.
  • Ingestion points: External data enters the context via gh run view --log-failed in Step 2, which fetches raw job logs.
  • Boundary markers: Absent. The skill does not define clear boundaries or provide instructions to the agent to disregard potential commands embedded within the logs.
  • Capability inventory: High-impact capabilities include GitHub CLI operations (gh api, gh run rerun), repository file modification (edit, commit, push), and the execution of arbitrary CLI commands (Step 5).
  • Sanitization: Absent. There is no evidence of log sanitization, filtering, or validation before the content is processed for root cause analysis.
  • [COMMAND_EXECUTION]: Step 5 explicitly instructs the agent to apply fixes via CLI commands if approved by the user. While this requires user approval, the specific commands are generated based on the interpretation of untrusted log data, creating a path for command injection.
  • [COMMAND_EXECUTION]: The skill utilizes a hardcoded repository path (khodo-lab/extralife) in Step 1. This could cause the agent to interact with an unintended repository or fail when analyzing runs from other projects.
  • [COMMAND_EXECUTION]: The skill uses python3 -c to execute inline Python code for YAML validation. While the code is static, it demonstrates a reliance on local interpreter execution for workflow tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — diagnose-workflow-failure