github-supply-chain-hardening-remediation

Warn

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands (e.g., gh repo clone, git switch -c, scorecard --repo) that interpolate user-supplied strings such as repository_full_name and branch_name. This presents a risk of command injection if the inputs are not properly sanitized.
  • [PROMPT_INJECTION]: The skill processes external data from a JSON proposal file (proposal_json_path) to determine which changes to apply. This represents an indirect prompt injection surface where a malicious proposal could trick the agent into committing backdoors or unintended changes to a repository.
  • Ingestion points: proposal_json_path file (SKILL.md).
  • Boundary markers: None specified for delimiting the JSON content from instructions.
  • Capability inventory: git commit, git push, gh pr create, and language-specific test runners (go test, npm test, cargo test) (SKILL.md).
  • Sanitization: Includes a leak check using grep to detect secrets in the diff before committing or pushing.
  • [EXTERNAL_DOWNLOADS]: Fetches source code and repository metadata from GitHub using the gh CLI and git. These operations target a well-known service for legitimate repository management tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 25, 2026, 07:34 PM
Security Audit — agent-trust-hub — github-supply-chain-hardening-remediation