github-delivery-watchdog

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The command template in commands/github-delivery-watchdog.md appends $ARGUMENTS directly after directing the agent to follow the skill's instructions. This creates a surface where a user could provide malicious input that conflicts with or overrides the skill's defined logic or bypasses its security gates.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the GitHub API, exposing it to potential indirect prompt injection vulnerabilities.
  • Ingestion points: The scripts/worker.py script fetches data from GitHub PRs via /pulls, Action runs via /actions/runs, and various commit statuses.
  • Boundary markers: The skill does not use explicit delimiters or instructions to separate instructions from the external, potentially attacker-influenced data found in pull requests or statuses.
  • Capability inventory: The script has write permissions on the repository, including the ability to update branches, add labels, and merge pull requests using the squash method.
  • Sanitization: The logic implements some sanitization by validating branch names against a specific regex (openhands/issue-\d+) and requiring explicit 'success' status strings from designated software factory tests and reviews before authorizing a merge.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — github-delivery-watchdog