github-multi-repo

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the Bash() tool to execute shell commands for repository discovery, cloning, and management. Examples include gh repo list, git push, and creating pull requests using the gh CLI.
  • [EXTERNAL_DOWNLOADS]: The skill downloads content from external GitHub repositories using gh repo clone and uses npx to execute the claude-flow tool and potentially other dependencies during npm install operations.
  • [REMOTE_CODE_EXECUTION]: The skill's core synchronization and testing workflows clone remote repositories to a temporary directory and execute npm install followed by npm test on the retrieved source code.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes data from external repositories.
  • Ingestion points: The skill reads package.json content and CLAUDE.md documentation files from various repositories via the GitHub API and clones repositories for local analysis (SKILL.md).
  • Boundary markers: None identified. The skill does not implement specific delimiters or instructions to ignore embedded prompts within the retrieved file contents.
  • Capability inventory: The skill possesses high-privilege capabilities including arbitrary shell command execution (Bash), repository creation (mcp__github__create_repository), and file modification (mcp__github__push_files).
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the content retrieved from remote repositories before it is processed or used to influence subsequent automated tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — github-multi-repo