scaffold-github-cloud-agent-environment
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits arbitrary project directories, which serves as a surface for indirect prompt injection if malicious data is present in the target repository.\n
- Ingestion points: The
scripts/audit_project.shscript scans the file system and extracts metadata (filenames, Makefile targets, runner labels) from the project being audited.\n - Boundary markers: The JSON output containing project metadata is passed to the agent; the skill does not explicitly wrap this data in delimiters or provide warnings for the LLM to ignore embedded instructions.\n
- Capability inventory: The skill can write or modify the
.github/workflows/copilot-setup-steps.ymlfile in the project directory.\n - Sanitization: Metadata is processed using standard utilities (
jq,rg), but the resulting strings are interpreted by the agent to make environment scaffolding decisions.\n- [COMMAND_EXECUTION]: The skill executes local shell scripts and python helpers usingsubprocess.runto perform repository auditing and workflow generation. This is constrained to the skill's internal logic and provided project paths.\n- [EXTERNAL_DOWNLOADS]: The skill identifies and references official GitHub documentation URLs to verify platform contracts. These references target a well-known service and are documented neutrally without alarming language.
Audit Metadata