upstream-fork-sync
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill requires and accesses a sensitive
GITHUB_PERSONAL_ACCESS_TOKENstored in the agent's secrets to perform repository synchronization tasks. - [COMMAND_EXECUTION]: Executes shell commands via
curlto verify GitHub credentials and to register new automations with the platform's internal API. - [DYNAMIC_EXECUTION]: Uses a piped shell command to execute a Python snippet (
curl ... | python3 -c ...) for parsing JSON responses from the GitHub API during token verification. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by interpolating user-provided text into a prompt for a downstream automation.
- Ingestion points: The
$LOCAL_CHANGESvariable, which accepts arbitrary user input inSKILL.md. - Boundary markers: Absent; the variable is directly inserted into the JSON payload of a
curlcommand without delimiters or warnings to the downstream LLM. - Capability inventory: The skill facilitates the creation of persistent cron automations that have the capability to execute git commands and project build/test scripts.
- Sanitization: Absent; the shell snippet performs simple string interpolation without escaping or validating the content of the
$LOCAL_CHANGESvariable.
Audit Metadata