github-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external GitHub repositories provided by the user. This creates a surface where an attacker could embed malicious instructions within a repository's documentation or source code to attempt to manipulate the agent's analysis or behavior.
  • Ingestion points: As described in SKILL.md, the agent clones external repositories and reads various files including README.md, ARCHITECTURE.md, and source code.
  • Boundary markers: The instructions do not define explicit delimiters or "ignore embedded instructions" warnings for the content read from external repositories.
  • Capability inventory: The skill utilizes shell tools (git, gh, tokei) and custom Python scripts (scripts/repo_stats.py, scripts/dependency_analyzer.py) to analyze the ingested data.
  • Sanitization: There is no evidence of sanitization, filtering, or escaping of external content before it is processed by the agent or interpolated into its context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:21 AM
Security Audit — agent-trust-hub — github-analyzer