github-delivery-watchdog
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The command template in
commands/github-delivery-watchdog.mdappends$ARGUMENTSdirectly after directing the agent to follow the skill's instructions. This creates a surface where a user could provide malicious input that conflicts with or overrides the skill's defined logic or bypasses its security gates. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the GitHub API, exposing it to potential indirect prompt injection vulnerabilities.
- Ingestion points: The
scripts/worker.pyscript fetches data from GitHub PRs via/pulls, Action runs via/actions/runs, and various commit statuses. - Boundary markers: The skill does not use explicit delimiters or instructions to separate instructions from the external, potentially attacker-influenced data found in pull requests or statuses.
- Capability inventory: The script has write permissions on the repository, including the ability to update branches, add labels, and merge pull requests using the squash method.
- Sanitization: The logic implements some sanitization by validating branch names against a specific regex (
openhands/issue-\d+) and requiring explicit 'success' status strings from designated software factory tests and reviews before authorizing a merge.
Audit Metadata