add-skill
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
scripts/fetch_skill.pyscript retrieves theGITHUB_TOKENenvironment variable and embeds it directly into the Git repository URL. - Evidence:
repo_url = f"https://{github_token}@github.com/{owner}/{repo}.git"(line 192). - Usage: The URL is passed as a command-line argument to
subprocess.run(['git', 'clone', ...]). - Risk: This practice can expose the sensitive token in system process listings (e.g.,
psoutput) or in the tool's error output and logs if the command fails. - [EXTERNAL_DOWNLOADS]: The skill is designed to download content from arbitrary GitHub repositories.
- Evidence:
scripts/fetch_skill.pyusesgit cloneandgit sparse-checkoutto fetch content from user-specified URLs. - Risk: Although targeting a well-known service, the lack of restriction on repository sources means it could be used to pull malicious code or instructions into the agent's workspace.
- [COMMAND_EXECUTION]: The implementation relies on executing system-level
gitcommands viasubprocess.run. - Evidence: Multiple calls to
subprocess.runare used inscripts/fetch_skill.pyto perform cloning, sparse-checkout initialization, and checking out content. - Risk: While the script avoids direct shell injection by using list-based argument passing, it acts on parameters derived from user-supplied GitHub URLs.
- [INDIRECT_PROMPT_INJECTION]: The skill imports
SKILL.mdinstruction files and associated scripts from external sources into the agent's workspace. - Evidence: The skill fetches external files and places them in the
.agents/skills/directory for the agent to load and use. - Risk: This creates a significant attack surface for indirect prompt injection, as there is no validation or sanitization of the imported content, allowing malicious instructions to be integrated into the agent's operational context.
Audit Metadata