together-ci-integration

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of repository-specific workflows and external API documentation, which theoretically exposes the agent to indirect prompt injection from those sources. However, the skill implements robust mitigation strategies. * Ingestion points: Local repository manifests and workflows (via Read, Glob, Grep) and external SDK/API documentation (via WebFetch). * Boundary markers: Explicit instructions for 'redaction tests', 'sanitized fixtures', and 'scrubbing prompts/responses'. * Capability inventory: The skill permits Write and Edit operations on CI configuration files. * Sanitization: Mandates the removal of credentials, tokens, and sensitive headers before publishing test evidence or logs.
  • [SAFE]: References to the Together AI Python SDK and official documentation are directed at legitimate, well-known service endpoints and official GitHub repositories. Use of the TOGETHER_API_KEY is handled following security best practices, such as environment masking and restricting access to protected jobs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 06:11 PM
Security Audit — agent-trust-hub — together-ci-integration