update-golden-values

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local repository scripts (download_golden_values.py, compare_golden_values_kl.py) and common shell commands for workspace management (git checkout, rm). These operations are consistent with the skill's primary purpose of maintaining test artifacts within the local environment.
  • [EXTERNAL_DOWNLOADS]: The skill installs the well-known Python packages click, python-gitlab, and requests from the official Python Package Index (PyPI) at runtime. These are standard dependencies for interacting with CI APIs and CLI arguments.
  • [CREDENTIALS_UNSAFE]: The workflow retrieves a GITHUB_TOKEN by invoking the gh auth token command. The skill instructions explicitly warn the user not to export this token into long-lived shell sessions or commit it to version control, promoting secure handling of temporary credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface where data from a CSV file is ingested to generate a PR summary.
  • Ingestion points: Data enters the context from /tmp/reldiff_summary.csv generated by the comparison script.
  • Boundary markers: The summary uses a predefined markdown template with specific placeholders for the calculated values.
  • Capability inventory: The skill has the ability to write to the local filesystem (updating golden values) and execute repository scripts.
  • Sanitization: The skill contains specific Python logic to cast CSV input fields to int and float before processing, effectively sanitizing the data and preventing arbitrary text from the file from being interpreted as instructions by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:19 PM
Security Audit — agent-trust-hub — update-golden-values