github-workflow-automation

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill implements AI-driven logic that processes untrusted data from external sources, creating a surface for indirect prompt injection. \n
  • Ingestion points: The workflows ingest pull request diffs (${{ steps.diff.outputs.diff }}), issue bodies (issue.body), and user comments (github.event.comment.body) directly into AI prompts in the ai-review.yml, issue-triage.yml, and mention-bot.yml files. \n
  • Boundary markers: There are no explicit boundary markers or "ignore embedded instructions" directives used when interpolating this external data into the prompts. \n
  • Capability inventory: The skill possesses capabilities to write to the repository, including creating PR reviews, adding labels to issues, commenting on issues, and modifying branch protection settings via actions/github-script. \n
  • Sanitization: No evidence of sanitization or validation of the ingested external content was found in the prompt templates. \n- [COMMAND_EXECUTION]: Several automation patterns involve the execution of shell commands. \n
  • The auto-rebase.yml workflow executes git rebase and git push --force-with-lease based on issue comment triggers. \n
  • The smartCherryPick utility uses an exec function to perform git operations like git show, git diff, and git cherry-pick using variables for commit hashes and branches. \n- [EXTERNAL_DOWNLOADS]: The skill utilizes several official and well-known integrations for its functionality. \n
  • It uses the @anthropic-ai/sdk Node.js package for AI interactions. \n
  • It leverages official GitHub Actions such as actions/checkout, actions/github-script, and actions/stale for repository operations. \n
  • It references tools and documentation from established sources like Google and Slack.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — github-workflow-automation