skills/jmerta/codex-skills/ci-fix/Gen Agent Trust Hub

ci-fix

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub Actions logs, which could contain malicious instructions.
  • Ingestion points: GitHub Actions logs retrieved via gh run view and gh api as specified in SKILL.md.
  • Boundary markers: Absent. The instructions do not define specific delimiters to isolate log content from the agent's internal reasoning or instruction set.
  • Capability inventory: The skill possesses the ability to write files (applying authorized fixes), execute shell commands (running local check equivalents and the gh tool), and perform network operations (pushing fixes or rerunning workflows).
  • Sanitization: While SKILL.md mandates that the agent "Never expose secrets from logs," there are no specific instructions for filtering or sanitizing log content for prompt injection attacks.
  • [COMMAND_EXECUTION]: The skill relies on the execution of shell commands through the GitHub CLI and local environment to perform diagnostics.
  • Evidence: SKILL.md explicitly lists commands like gh pr checks, gh run view, and gh api, and instructs the agent to "Run the closest local equivalent" of CI steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 10:20 AM