github-bot
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on local shell scripts and system utilities such as
openssl,curl, andpython3to facilitate API authentication and data processing. It executes a local scriptscripts/github-token.shto generate GitHub App installation tokens. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data sources such as GitHub Issues, Pull Requests, and repository content, which are untrusted and could contain malicious instructions. The skill has the capability to perform write operations (e.g., creating PRs, merging code, pushing commits) based on this data.
- Ingestion points: Fetches data from GitHub API endpoints (e.g.,
https://api.github.com/repos/OWNER/REPO/...). - Boundary markers: No explicit boundary markers or 'ignore' instructions for external content are defined in the skill documentation.
- Capability inventory: Includes the ability to perform network operations, modify repository content, and manage Pull Requests and Issues.
- Sanitization: The skill does not demonstrate explicit sanitization or schema validation of the content retrieved from GitHub before it is processed by the agent.
Audit Metadata