suggest-awesome-github-copilot-skills
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation, skill definitions, and associated assets from the
github/awesome-copilotrepository. These operations target a known and established repository infrastructure. - [COMMAND_EXECUTION]: The instructions permit the use of
curlvia a terminal tool to download assets. This is used as a fallback to standard fetch tools to ensure the integrity of the downloaded content. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process Markdown content from remote sources, including the
README.skills.mdand variousSKILL.mdfiles from the remote repository. - Ingestion points: Remote README and individual skill definition files are read into the agent context (SKILL.md).
- Boundary markers: The skill does not explicitly define delimiters for the ingested remote content.
- Capability inventory: The skill has the capability to write files to the
.github/skills/directory and execute network requests via#fetchandcurl(SKILL.md). - Sanitization: There are no specified sanitization routines for the remote content before processing.
Audit Metadata