github-trending

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill demonstrates secure secret management by utilizing environment variables (process.env.GITHUB_TOKEN) for API authentication rather than hardcoding sensitive credentials.
  • [EXTERNAL_DOWNLOADS]: The implementation examples reference the cheerio library for HTML parsing.
  • [DATA_EXFILTRATION]: The skill performs network operations exclusively targeting well-known services (GitHub's main and API domains) to retrieve trending project information.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external web pages, creating a surface for potential indirect prompt injection.
  • Ingestion points: Data is fetched from https://github.com/trending and the GitHub Search API as described in SKILL.md.
  • Boundary markers: The scraped data is parsed into structured objects before being used, reducing the risk of accidental instruction execution.
  • Capability inventory: The skill utilizes fetch for network requests and cheerio for content parsing.
  • Sanitization: URL parameters are properly encoded using encodeURIComponent before interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:28 AM
Security Audit — agent-trust-hub — github-trending