buildspace-ci-cd

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill configures workflows that utilize AI to analyze untrusted input, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Workflows such as check-readme.yaml, check-skills.yaml, and various release pipelines ingest PR diffs, commit messages, and repository file content (README.md, SKILL.md) for AI analysis.
  • Boundary markers: The instructions do not define boundary markers or explicit instructions for the AI to ignore embedded commands within the ingested data.
  • Capability inventory: The workflows are granted elevated permissions (contents: write, pull-requests: write) and have the capability to publish packages to external registries like npm and crates.io.
  • Sanitization: There is no mention of sanitization or filtering of the external PR content before it is processed by the LLM.
  • [COMMAND_EXECUTION]: The skill provides guidance for configuring workflows that execute standard build and packaging commands, including bun run build, go build, swift build, and make release across various environments.
  • [EXTERNAL_DOWNLOADS]: The skill references and utilizes external reusable GitHub Actions workflows hosted in the photon-hq/buildspace repository to implement the release automation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:16 PM
Security Audit — agent-trust-hub — buildspace-ci-cd