contributing-to-pi

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform standard development tasks including repository cloning, worktree management, and package installation via git, npm, and gh CLI tools.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates reading external data from local repository documentation (CONTRIBUTING.md, AGENTS.md) and GitHub issue comments. This creates a potential surface for indirect prompt injection if these sources contain malicious instructions.\n
  • Ingestion points: CONTRIBUTING.md, AGENTS.md, and output from gh issue view.\n
  • Boundary markers: None specified in the instructions.\n
  • Capability inventory: Shell command execution via npm install, npm run check, and git.\n
  • Sanitization: None specified; relies on default model behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — contributing-to-pi