github-search

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong imperative language like 'The Prime Directive' and 'No exceptions' to enforce a research-first methodology. This is natural instructional language intended to shape the agent's task-specific persona and does not attempt to override safety protocols or extract system prompts.\n- [DATA_EXFILTRATION]: The skill identifies and recommends searching well-known and trusted services such as GitHub, NPM, PyPI, and Crates.io. These are standard resources for developer tools and do not involve unauthorized access to sensitive local data or exfiltration to malicious domains.\n- [PROMPT_INJECTION]: (Indirect Prompt Injection Surface) The workflow involves the ingestion and analysis of external data from unvetted public repositories, which is a functional requirement of the skill's purpose.\n
  • Ingestion points: README files, code patterns, and repository metadata from public GitHub projects and package registries (SKILL.md).\n
  • Boundary markers: The skill suggests using structured templates to report findings but does not define explicit delimiters to separate external data from agent instructions.\n
  • Capability inventory: The skill body focuses on research and pattern harvesting; it does not request tool access for shell execution, file system writes, or automated software installation.\n
  • Sanitization: No specific sanitization or validation steps are provided for the content retrieved from external sources before it is analyzed or reported.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 07:45 PM
Security Audit — agent-trust-hub — github-search