triage-ci-failure

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the GitHub CLI (gh) and standard developer tools such as npm, jest, and pytest to retrieve logs and reproduce failures locally. These actions align with the skill's stated purpose and use well-known, legitimate software.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted CI logs.
  • Ingestion points: CI job logs retrieved via gh run view or provided by the user in SKILL.md.
  • Boundary markers: Absent; instructions do not specify the use of delimiters or warnings to ignore commands embedded in log data.
  • Capability inventory: Execution of various shell-based tools (gh, npm, npx, pytest, jest, vitest).
  • Sanitization: Absent; the agent is instructed to interpret logs directly to generate commands and fixes without a validation or sanitization layer.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:13 AM
Security Audit — agent-trust-hub — triage-ci-failure