github-workflow-automation
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill implements AI-driven logic that processes untrusted data from external sources, creating a surface for indirect prompt injection. \n
- Ingestion points: The workflows ingest pull request diffs (
${{ steps.diff.outputs.diff }}), issue bodies (issue.body), and user comments (github.event.comment.body) directly into AI prompts in theai-review.yml,issue-triage.yml, andmention-bot.ymlfiles. \n - Boundary markers: There are no explicit boundary markers or "ignore embedded instructions" directives used when interpolating this external data into the prompts. \n
- Capability inventory: The skill possesses capabilities to write to the repository, including creating PR reviews, adding labels to issues, commenting on issues, and modifying branch protection settings via
actions/github-script. \n - Sanitization: No evidence of sanitization or validation of the ingested external content was found in the prompt templates. \n- [COMMAND_EXECUTION]: Several automation patterns involve the execution of shell commands. \n
- The
auto-rebase.ymlworkflow executesgit rebaseandgit push --force-with-leasebased on issue comment triggers. \n - The
smartCherryPickutility uses anexecfunction to perform git operations likegit show,git diff, andgit cherry-pickusing variables for commit hashes and branches. \n- [EXTERNAL_DOWNLOADS]: The skill utilizes several official and well-known integrations for its functionality. \n - It uses the
@anthropic-ai/sdkNode.js package for AI interactions. \n - It leverages official GitHub Actions such as
actions/checkout,actions/github-script, andactions/stalefor repository operations. \n - It references tools and documentation from established sources like Google and Slack.
Audit Metadata