ci-fix
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub Actions logs, which could contain malicious instructions.
- Ingestion points: GitHub Actions logs retrieved via
gh run viewandgh apias specified inSKILL.md. - Boundary markers: Absent. The instructions do not define specific delimiters to isolate log content from the agent's internal reasoning or instruction set.
- Capability inventory: The skill possesses the ability to write files (applying authorized fixes), execute shell commands (running local check equivalents and the
ghtool), and perform network operations (pushing fixes or rerunning workflows). - Sanitization: While
SKILL.mdmandates that the agent "Never expose secrets from logs," there are no specific instructions for filtering or sanitizing log content for prompt injection attacks. - [COMMAND_EXECUTION]: The skill relies on the execution of shell commands through the GitHub CLI and local environment to perform diagnostics.
- Evidence:
SKILL.mdexplicitly lists commands likegh pr checks,gh run view, andgh api, and instructs the agent to "Run the closest local equivalent" of CI steps.
Audit Metadata