gic-coding-agent-skills

Pass

Audited by Gen Agent Trust Hub on Jun 9, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with external data sources such as GitHub pull requests, CI/CD check runs, and review comments. This establishes an indirect prompt injection surface where malicious repository content could potentially influence agent behavior. However, the instructions mitigate this risk by enforcing strict secret management and requiring the use of specific platform tools for merging.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the use of established third-party libraries including the @chenglou/pretext NPM package for text layout and GSAP for animations. These are well-known resources in the development community.
  • [COMMAND_EXECUTION]: Instructions include the use of a custom CLI tool named cofounder (e.g., cofounder run create_managed_stripe_product) to handle Stripe integration tasks. This is documented as a standard engineering workflow for the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 9, 2026, 09:34 PM
Security Audit — agent-trust-hub — gic-coding-agent-skills