mcp-github

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process untrusted data from external GitHub resources, creating a surface for indirect prompt injection.
  • Ingestion points: GitHub issue details, PR context, review comments, and discussions (as specified in SKILL.md).
  • Boundary markers: Absent. The instructions do not define delimiters or specific guidance for the agent to treat external GitHub content as untrusted data rather than instructions.
  • Capability inventory: The skill utilizes GitHub MCP tools which include remote mutation capabilities (creating or updating remote resources as mentioned in workflow step 4).
  • Sanitization: Absent. No instructions are provided to sanitize or validate the content retrieved from GitHub before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:02 PM
Security Audit — agent-trust-hub — mcp-github