githits-mcp

Pass

Audited by Gen Agent Trust Hub on Oct 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an instructional routing guide for external tools. It contains no executable code, obfuscation, or malicious patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill explicitly identifies and mitigates the risk of indirect prompt injection. It instructs the agent to treat all retrieved OSS content (READMEs, code, comments, etc.) as untrusted third-party evidence rather than instructions. It further directs the agent to verify claims against structured fields and to disregard embedded commands (shell, install, etc.) or destination URLs found in the retrieved data.
  • [DATA_EXFILTRATION]: The instructions include a clear directive to only use the tools for public Open Source Software (OSS) and strictly forbids sending local, private, or proprietary source code to the tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 10, 2026, 03:35 AM