github
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and act upon content from external, untrusted sources. (1) Ingestion points: Pull request summaries, issue templates, and commit messages are processed during governance workflows. (2) Boundary markers: No specific delimiters or instructions to ignore embedded commands within the processed data are provided. (3) Capability inventory: The skill utilizes
gitandghCLI tools for repository operations, representing a capability to perform actions based on input. (4) Sanitization: There is no mention of sanitizing or validating the content of PRs or issues before the agent processes them. - [COMMAND_EXECUTION]: The instructions and reference documents utilize
git,gh(GitHub CLI), andrg(ripgrep) for their intended purposes of repository management and documentation indexing. - [EXTERNAL_DOWNLOADS]: The documentation references official and well-known GitHub Actions (such as
actions/checkoutandactions/dependency-review-action) and services like Dependabot for standard CI/CD and dependency management.
Audit Metadata