contributing-to-pi
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform standard development tasks including repository cloning, worktree management, and package installation via
git,npm, andghCLI tools.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates reading external data from local repository documentation (CONTRIBUTING.md,AGENTS.md) and GitHub issue comments. This creates a potential surface for indirect prompt injection if these sources contain malicious instructions.\n - Ingestion points:
CONTRIBUTING.md,AGENTS.md, and output fromgh issue view.\n - Boundary markers: None specified in the instructions.\n
- Capability inventory: Shell command execution via
npm install,npm run check, andgit.\n - Sanitization: None specified; relies on default model behavior.
Audit Metadata