github-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external GitHub repositories provided by the user. This creates a surface where an attacker could embed malicious instructions within a repository's documentation or source code to attempt to manipulate the agent's analysis or behavior.
- Ingestion points: As described in
SKILL.md, the agent clones external repositories and reads various files including README.md, ARCHITECTURE.md, and source code. - Boundary markers: The instructions do not define explicit delimiters or "ignore embedded instructions" warnings for the content read from external repositories.
- Capability inventory: The skill utilizes shell tools (
git,gh,tokei) and custom Python scripts (scripts/repo_stats.py,scripts/dependency_analyzer.py) to analyze the ingested data. - Sanitization: There is no evidence of sanitization, filtering, or escaping of external content before it is processed by the agent or interpolated into its context.
Audit Metadata