github

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and act upon content from external, untrusted sources. (1) Ingestion points: Pull request summaries, issue templates, and commit messages are processed during governance workflows. (2) Boundary markers: No specific delimiters or instructions to ignore embedded commands within the processed data are provided. (3) Capability inventory: The skill utilizes git and gh CLI tools for repository operations, representing a capability to perform actions based on input. (4) Sanitization: There is no mention of sanitizing or validating the content of PRs or issues before the agent processes them.
  • [COMMAND_EXECUTION]: The instructions and reference documents utilize git, gh (GitHub CLI), and rg (ripgrep) for their intended purposes of repository management and documentation indexing.
  • [EXTERNAL_DOWNLOADS]: The documentation references official and well-known GitHub Actions (such as actions/checkout and actions/dependency-review-action) and services like Dependabot for standard CI/CD and dependency management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 12:57 AM
Security Audit — agent-trust-hub — github