mcore-cicd
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external data from CI logs and GitHub PR metadata, creating a vulnerability surface where malicious content in those sources could influence agent behavior.
- Ingestion points: PR metadata (title, labels, author) via
gh pr view, PR diffs viagh pr diff, and log artifacts downloaded from GitHub Actions viagh run download. - Boundary markers: The instructions do not define clear delimiters or provide instructions for the agent to ignore embedded commands within the processed log files.
- Capability inventory: The skill uses
ghCLI for repository interaction, local shell tools (grep,sed,wc) for log processing, and a Python script for remote repository interaction. - Sanitization: There are no documented steps for sanitizing or escaping the content of the logs before processing.
- [COMMAND_EXECUTION]: The skill provides instructions for triggering an internal CI pipeline using
tools/trigger_internal_ci.py, which performs a force-push to a remote GitLab repository. While the skill includes a prominent warning about the destructive nature of this command and mandates a--dry-runpreflight check, it remains a high-risk operation that requires careful oversight.
Audit Metadata