scaffold-github-cloud-agent-environment

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill audits arbitrary project directories, which serves as a surface for indirect prompt injection if malicious data is present in the target repository.\n
  • Ingestion points: The scripts/audit_project.sh script scans the file system and extracts metadata (filenames, Makefile targets, runner labels) from the project being audited.\n
  • Boundary markers: The JSON output containing project metadata is passed to the agent; the skill does not explicitly wrap this data in delimiters or provide warnings for the LLM to ignore embedded instructions.\n
  • Capability inventory: The skill can write or modify the .github/workflows/copilot-setup-steps.yml file in the project directory.\n
  • Sanitization: Metadata is processed using standard utilities (jq, rg), but the resulting strings are interpreted by the agent to make environment scaffolding decisions.\n- [COMMAND_EXECUTION]: The skill executes local shell scripts and python helpers using subprocess.run to perform repository auditing and workflow generation. This is constrained to the skill's internal logic and provided project paths.\n- [EXTERNAL_DOWNLOADS]: The skill identifies and references official GitHub documentation URLs to verify platform contracts. These references target a well-known service and are documented neutrally without alarming language.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:40 AM
Security Audit — agent-trust-hub — scaffold-github-cloud-agent-environment