skills/niekcandaele/skills/check-ci/Gen Agent Trust Hub

check-ci

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing untrusted data from external sources.
  • Ingestion points: External CI/CD job logs and pipeline statuses are fetched via CLI tools (gh, glab) as described in SKILL.md.
  • Boundary markers: The prompt template for the debugger skill lacks explicit delimiters (such as XML tags or unique markers) or instructions to treat the interpolated log excerpts as untrusted content.
  • Capability inventory: The skill utilizes the Bash tool for platform detection and log retrieval, and the Skill tool for invoking secondary analysis workflows.
  • Sanitization: No sanitization, filtering, or validation of the log content is performed before it is passed to the AI, which could allow malicious content embedded in logs to influence the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 01:23 PM
Security Audit — agent-trust-hub — check-ci