oss-forensics
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting and processing untrusted data from external GitHub repositories.
- Ingestion points: Data enters the agent context during Phase 2 when cloning repositories, querying issues, PRs, and commit history.
- Boundary markers: The skill implements 'Anti-Hallucination Guardrails' to enforce evidence-based reporting and separation of hypotheses from facts, though these do not fully prevent adversarial content from influencing the agent.
- Capability inventory: The agent has access to shell commands (git, curl, bq), file operations, and execution of local Python scripts.
- Sanitization: There is no explicit sanitization of the content fetched from target repositories before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill instructions include numerous shell commands for repository analysis and data management.
- Evidence: Commands include
git clone,git log,git fsck,curlfor API access, andbq queryfor BigQuery forensics. - Context: These commands are necessary for the skill's primary purpose of performing security forensics and are executed locally or against well-known services.
- [EXTERNAL_DOWNLOADS]: The skill fetches data from multiple external sources to build an evidence store.
- Evidence: It clones repositories from GitHub, queries the GitHub REST API, and fetches archived snapshots from the Wayback Machine (web.archive.org).
- Context: These operations target well-known and established services for legitimate investigative data collection.
Audit Metadata