triage-ci-failure
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the GitHub CLI (
gh) and standard developer tools such asnpm,jest, andpytestto retrieve logs and reproduce failures locally. These actions align with the skill's stated purpose and use well-known, legitimate software. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted CI logs.
- Ingestion points: CI job logs retrieved via
gh run viewor provided by the user inSKILL.md. - Boundary markers: Absent; instructions do not specify the use of delimiters or warnings to ignore commands embedded in log data.
- Capability inventory: Execution of various shell-based tools (
gh,npm,npx,pytest,jest,vitest). - Sanitization: Absent; the agent is instructed to interpret logs directly to generate commands and fixes without a validation or sanitization layer.
Audit Metadata