github-agentic-workflows

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the gh-aw CLI extension and workflow templates from official GitHub repositories.
  • [COMMAND_EXECUTION]: Includes commands for installing extensions and managing agentic workflows using the GitHub CLI (gh).
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when processing external repository data (issues, comments). It mitigates this via a documented 5-layer security model that includes safe output guardrails (prefixes, label allowlists), containerized sandboxing, and read-only tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:14 PM
Security Audit — agent-trust-hub — github-agentic-workflows