github-stale-ci-pr-closer

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub pull request comments and CI check results to influence its maintenance logic. For instance, an author's comment can reset the staleness timer.
  • Ingestion points: scripts/worker.py fetches comment bodies and status check names via the GitHub API.
  • Boundary markers: Not applicable as the skill uses deterministic string matching for internal markers (e.g., <!-- openhands-stale-ci-warning -->) rather than LLM processing.
  • Capability inventory: The skill has the ability to post comments and close pull requests via the GitHub API.
  • Sanitization: The script uses simple string containment checks to identify its own markers, ensuring that user-provided content is not interpreted as instructions.
  • [COMMAND_EXECUTION]: The script performs legitimate network operations to interact with the GitHub API and an internal Key-Value (KV) service to persist automation state. These operations are conducted using standard Python urllib calls with appropriate URL sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:36 PM
Security Audit — agent-trust-hub — github-stale-ci-pr-closer