buildspace-ci-cd
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill configures workflows that utilize AI to analyze untrusted input, creating a surface for indirect prompt injection attacks.
- Ingestion points: Workflows such as
check-readme.yaml,check-skills.yaml, and various release pipelines ingest PR diffs, commit messages, and repository file content (README.md,SKILL.md) for AI analysis. - Boundary markers: The instructions do not define boundary markers or explicit instructions for the AI to ignore embedded commands within the ingested data.
- Capability inventory: The workflows are granted elevated permissions (
contents: write,pull-requests: write) and have the capability to publish packages to external registries like npm and crates.io. - Sanitization: There is no mention of sanitization or filtering of the external PR content before it is processed by the LLM.
- [COMMAND_EXECUTION]: The skill provides guidance for configuring workflows that execute standard build and packaging commands, including
bun run build,go build,swift build, andmake releaseacross various environments. - [EXTERNAL_DOWNLOADS]: The skill references and utilizes external reusable GitHub Actions workflows hosted in the
photon-hq/buildspacerepository to implement the release automation logic.
Audit Metadata