prcheckloop

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes GitHub Action logs to identify and fix build failures. Because these logs can contain arbitrary text from the build environment, an attacker could potentially embed instructions to mislead the agent.\n
  • Ingestion points: The skill uses gh run view --log-failed (SKILL.md) to read output from external CI/CD processes.\n
  • Boundary markers: None present. The instructions do not specify that the agent should ignore instructions found within the logs.\n
  • Capability inventory: The skill possesses the capability to modify files, execute commands locally for reproduction, and push changes to the repository via git push (SKILL.md).\n
  • Sanitization: No sanitization or filtering of the log content is performed before the agent analyzes it for fixes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:47 PM
Security Audit — agent-trust-hub — prcheckloop