kmp-ci-github-actions

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The pr-visual-evidence-workflow.md reference describes a workflow that interacts with pull request comments using the gh API. It fetches comment history to identify and update its own visual evidence summaries. This represents an ingestion point for untrusted data from the GitHub environment.
  • Ingestion points: Pull request comments fetched via gh api "repos/$REPO/issues/$PR/comments" in references/pr-visual-evidence-workflow.md.
  • Boundary markers: The workflow utilizes a marker <!-- pr-visual-evidence --> to filter comments, but does not implement specific sanitization for the content of the comments it processes.
  • Capability inventory: The workflow involves shell script execution, local Python script invocation (python3 scripts/pr_visual_evidence.py), and GitHub API write access to post or update comments.
  • Sanitization: The logic is limited to identifying comment IDs based on a specific prefix; it does not sanitize the input for downstream processing beyond redirection to a markdown file.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of developer tools from well-known services. Specifically, scripts/install-act.sh uses the Homebrew package manager to install act (brew install act), a standard tool for running GitHub Actions locally.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution across its provided scripts and suggested workflow configurations. This includes Gradle wrapper commands (./gradlew), Homebrew package management, Docker-based local CI runs via act, and GitHub CLI (gh) operations for repository interaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:23 AM
Security Audit — agent-trust-hub — kmp-ci-github-actions