diagnosing-ci-and-merge-bottlenecks

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured instructions for using specialized Model Context Protocol (MCP) tools to diagnose pipeline bottlenecks. It does not contain any commands for arbitrary code execution, privilege escalation, or persistence.
  • [SAFE]: All external references, including GitHub repositories and data warehouse tools, are official resources belonging to the skill's author. No suspicious domains, typosquatted packages, or obfuscated URLs were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub, such as pull request descriptions and commit statuses, which represents an indirect prompt injection surface. The capabilities of the skill are limited to read-only diagnostic operations, mitigating potential risks associated with malicious data content.
  • Ingestion points: Pull request metadata and workflow run data retrieved from GitHub in SKILL.md.
  • Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for the processed external data.
  • Capability inventory: Limited to specific diagnostic MCP tool calls; no subprocess, network-egress, or file-write capabilities are present in the skill body.
  • Sanitization: The skill does not describe specific sanitization steps, relying instead on the underlying tool implementation and standard LLM safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:06 AM
Security Audit — agent-trust-hub — diagnosing-ci-and-merge-bottlenecks