skills/johnlindquist/claude/workflow/Gen Agent Trust Hub

workflow

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides installation instructions (curl -sS https://webi.sh/gh | sh) that download and execute code from an external server directly in the system shell. This pattern allows for the execution of unverified remote code from a third-party source without integrity checks or local auditing.
  • [EXTERNAL_DOWNLOADS]: The skill references an installer from webi.sh, which is an external entity not identified as a trusted vendor or official distribution channel for the GitHub CLI.
  • [COMMAND_EXECUTION]: The skill uses the GitHub CLI (gh) to execute shell-based operations including managing CI/CD runs, viewing logs, and downloading files, which involve interactions with the network and local operating system.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of raw logs from GitHub Actions via the gh run view --log command. Because logs can contain output from any process running in the CI environment, they represent an attack surface where a malicious actor could embed instructions designed to influence the behavior of the agent reading the log.
  • Ingestion points: GitHub Action logs retrieved via gh run view as referenced in SKILL.md.
  • Boundary markers: Absent; log output is ingested as raw text.
  • Capability inventory: File system writing via gh run download and workflow control via gh run rerun and gh workflow run.
  • Sanitization: Absent; the skill does not implement any filtering or escaping for content retrieved from logs.
Recommendations
  • HIGH: Downloads and executes remote code from: https://webi.sh/gh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 08:26 PM
Security Audit — agent-trust-hub — workflow