github-trending
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill demonstrates secure secret management by utilizing environment variables (
process.env.GITHUB_TOKEN) for API authentication rather than hardcoding sensitive credentials. - [EXTERNAL_DOWNLOADS]: The implementation examples reference the
cheeriolibrary for HTML parsing. - [DATA_EXFILTRATION]: The skill performs network operations exclusively targeting well-known services (GitHub's main and API domains) to retrieve trending project information.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external web pages, creating a surface for potential indirect prompt injection.
- Ingestion points: Data is fetched from
https://github.com/trendingand the GitHub Search API as described inSKILL.md. - Boundary markers: The scraped data is parsed into structured objects before being used, reducing the risk of accidental instruction execution.
- Capability inventory: The skill utilizes
fetchfor network requests andcheeriofor content parsing. - Sanitization: URL parameters are properly encoded using
encodeURIComponentbefore interpolation.
Audit Metadata