skills/rheinmir/dym/dym-setup-ci/Gen Agent Trust Hub

dym-setup-ci

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a CI process that processes markdown files which could contain untrusted instructions.\n
  • Ingestion points: The GitHub Actions workflow identifies modified .md files using git diff to pass them to a validator.\n
  • Boundary markers: The provided configuration does not include explicit markers or instructions for the agent to ignore embedded content within the processed files.\n
  • Capability inventory: The CI environment executes a local Python validator script (llmwiki-validate.py) to analyze the markdown files.\n
  • Sanitization: No content sanitization is described in the provided configuration.\n- [EXTERNAL_DOWNLOADS]: The configuration involves installing common software packages from official registries.\n
  • The CI workflow installs the pyyaml library from the official Python Package Index (PyPI).\n
  • The instructions suggest installing the pre-commit tool using standard package managers like pip or pipx.\n- [COMMAND_EXECUTION]: The skill configures the execution of local scripts and shell commands in a CI environment.\n
  • The GitHub Actions workflow executes llmwiki-validate.py from the repository's .harness directory.\n
  • The instructions describe running local scripts such as gen-converters.py for configuration generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 06:23 AM