oss-forensics

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting and processing untrusted data from external GitHub repositories.
  • Ingestion points: Data enters the agent context during Phase 2 when cloning repositories, querying issues, PRs, and commit history.
  • Boundary markers: The skill implements 'Anti-Hallucination Guardrails' to enforce evidence-based reporting and separation of hypotheses from facts, though these do not fully prevent adversarial content from influencing the agent.
  • Capability inventory: The agent has access to shell commands (git, curl, bq), file operations, and execution of local Python scripts.
  • Sanitization: There is no explicit sanitization of the content fetched from target repositories before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill instructions include numerous shell commands for repository analysis and data management.
  • Evidence: Commands include git clone, git log, git fsck, curl for API access, and bq query for BigQuery forensics.
  • Context: These commands are necessary for the skill's primary purpose of performing security forensics and are executed locally or against well-known services.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from multiple external sources to build an evidence store.
  • Evidence: It clones repositories from GitHub, queries the GitHub REST API, and fetches archived snapshots from the Wayback Machine (web.archive.org).
  • Context: These operations target well-known and established services for legitimate investigative data collection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 05:29 AM