contribute

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the gh and git CLI tools to automate the contribution workflow. These commands are executed locally using the user's existing credentials and are orchestrated by a series of shell and Python scripts. The execution is deterministic and primarily involves querying repository state or staging commits.
  • [EXTERNAL_DOWNLOADS]: The researcher-build.sh script downloads metadata and documentation files (like CONTRIBUTING.md) from public GitHub repositories using the gh API. It also optionally follows up to 15 depth-1 links found within these documents to gather additional contribution rules. Downloads are limited in size (50KB) and are used for information gathering rather than direct execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an inherent indirect prompt injection surface as it is designed to analyze untrusted documentation from public repositories to extract rules.
  • Ingestion points: researcher-build.sh (and the researcher agent) fetches CONTRIBUTING.md and related external links from arbitrary public repositories during the intake phase.
  • Boundary markers: Content is aggregated into local text files (all-text.txt) without special delimiters before being read by the agent.
  • Capability inventory: The skill uses broad tools like Bash, Write, and Edit to manage the local environment and draft PRs.
  • Sanitization: The risk is mitigated by a deterministic 'gate' system that validates extracted data. For example, b16-local-check-allowlist.sh ensures that any test command extracted from documentation matches a safe allowlist and does not contain shell metacharacters before it can be processed by other components. This is a core feature for the skill's primary purpose.
  • [SAFE]: The skill includes advanced security features, such as a PreToolUse hook (precheck-hook.sh) that intercepts sensitive GitHub CLI commands to ensure they pass a security 'gate' verdict. It also implements specific checks for shell injection, SSRF, and sensitive data leakage, representing a high level of security awareness and protective measures for the user environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 04:41 AM
Security Audit — agent-trust-hub — contribute