github-supply-chain-hardening-remediation
Warn
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands (e.g.,
gh repo clone,git switch -c,scorecard --repo) that interpolate user-supplied strings such asrepository_full_nameandbranch_name. This presents a risk of command injection if the inputs are not properly sanitized. - [PROMPT_INJECTION]: The skill processes external data from a JSON proposal file (
proposal_json_path) to determine which changes to apply. This represents an indirect prompt injection surface where a malicious proposal could trick the agent into committing backdoors or unintended changes to a repository. - Ingestion points:
proposal_json_pathfile (SKILL.md). - Boundary markers: None specified for delimiting the JSON content from instructions.
- Capability inventory:
git commit,git push,gh pr create, and language-specific test runners (go test,npm test,cargo test) (SKILL.md). - Sanitization: Includes a leak check using
grepto detect secrets in the diff before committing or pushing. - [EXTERNAL_DOWNLOADS]: Fetches source code and repository metadata from GitHub using the
ghCLI andgit. These operations target a well-known service for legitimate repository management tasks.
Audit Metadata