mcp-github
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process untrusted data from external GitHub resources, creating a surface for indirect prompt injection.
- Ingestion points: GitHub issue details, PR context, review comments, and discussions (as specified in SKILL.md).
- Boundary markers: Absent. The instructions do not define delimiters or specific guidance for the agent to treat external GitHub content as untrusted data rather than instructions.
- Capability inventory: The skill utilizes GitHub MCP tools which include remote mutation capabilities (creating or updating remote resources as mentioned in workflow step 4).
- Sanitization: Absent. No instructions are provided to sanitize or validate the content retrieved from GitHub before processing.
Audit Metadata