github-stale-ci-pr-closer
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub pull request comments and CI check results to influence its maintenance logic. For instance, an author's comment can reset the staleness timer.
- Ingestion points:
scripts/worker.pyfetches comment bodies and status check names via the GitHub API. - Boundary markers: Not applicable as the skill uses deterministic string matching for internal markers (e.g.,
<!-- openhands-stale-ci-warning -->) rather than LLM processing. - Capability inventory: The skill has the ability to post comments and close pull requests via the GitHub API.
- Sanitization: The script uses simple string containment checks to identify its own markers, ensuring that user-provided content is not interpreted as instructions.
- [COMMAND_EXECUTION]: The script performs legitimate network operations to interact with the GitHub API and an internal Key-Value (KV) service to persist automation state. These operations are conducted using standard Python
urllibcalls with appropriate URL sanitization.
Audit Metadata