rhdh-overlay-cve-export

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes git and gh CLI tools using spawnSync to retrieve commit history, file contents, and pull request information from a remote repository.
  • [EXTERNAL_DOWNLOADS]: The script clones the rhdh-plugin-export-overlays repository from the developer's GitHub organization to a local temporary directory for analysis.
  • [PROMPT_INJECTION]: The skill processes external data including git commit messages and PR bodies. It mitigates indirect prompt injection risks by using strict regex-based filtering to extract specific CVE and Jira patterns and by outputting structured data, which serves as a boundary between the untrusted input and the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 03:41 PM
Security Audit — agent-trust-hub — rhdh-overlay-cve-export