github-agents-md-maintainer
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The automation script (
scripts/main.py) usessubprocess.runto executegitcommands for cloning, committing, and pushing changes. These commands are executed without a shell (shell=False), and repository names are validated against a specific regular expression to prevent command injection. - [INDIRECT_PROMPT_INJECTION]: The skill instructs an AI agent to read and analyze the contents of external GitHub repositories. This content is untrusted and could contain malicious instructions. The skill mitigates this risk by including defensive instructions in the agent's prompt, explicitly telling it to ignore any non-task-related commands found in the repository files.
- Ingestion points: Files and metadata from cloned GitHub repositories (specifically in
_build_maintenance_prompt). - Boundary markers: The prompt includes a specific section warning the agent that repository contents are untrusted and providing clear rules for the task.
- Capability inventory: The agent is granted
terminalandfile_editortools, as well as a GitHub token for branch pushing and pull request creation. - Sanitization: The script does not programmatically sanitize or filter repository content before it is read by the agent, relying on instructions for safety.
- [DYNAMIC_EXECUTION]: During the setup workflow (
SKILL.md), the skill generates a customized automation script by substituting user-provided configuration (like repository lists and branch prefixes) into a template. This script is then compiled and executed on a schedule. - [EXTERNAL_DOWNLOADS]: The skill clones source code from external GitHub repositories to perform its documentation maintenance tasks. These downloads are performed from a well-known service (GitHub) using standard tooling.
Audit Metadata