update-golden-values
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local repository scripts (
download_golden_values.py,compare_golden_values_kl.py) and common shell commands for workspace management (git checkout,rm). These operations are consistent with the skill's primary purpose of maintaining test artifacts within the local environment. - [EXTERNAL_DOWNLOADS]: The skill installs the well-known Python packages
click,python-gitlab, andrequestsfrom the official Python Package Index (PyPI) at runtime. These are standard dependencies for interacting with CI APIs and CLI arguments. - [CREDENTIALS_UNSAFE]: The workflow retrieves a
GITHUB_TOKENby invoking thegh auth tokencommand. The skill instructions explicitly warn the user not to export this token into long-lived shell sessions or commit it to version control, promoting secure handling of temporary credentials. - [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface where data from a CSV file is ingested to generate a PR summary.
- Ingestion points: Data enters the context from
/tmp/reldiff_summary.csvgenerated by the comparison script. - Boundary markers: The summary uses a predefined markdown template with specific placeholders for the calculated values.
- Capability inventory: The skill has the ability to write to the local filesystem (updating golden values) and execute repository scripts.
- Sanitization: The skill contains specific Python logic to cast CSV input fields to
intandfloatbefore processing, effectively sanitizing the data and preventing arbitrary text from the file from being interpreted as instructions by the agent.
Audit Metadata