github-multi-repo
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
Bash()tool to execute shell commands for repository discovery, cloning, and management. Examples includegh repo list,git push, and creating pull requests using theghCLI. - [EXTERNAL_DOWNLOADS]: The skill downloads content from external GitHub repositories using
gh repo cloneand usesnpxto execute theclaude-flowtool and potentially other dependencies duringnpm installoperations. - [REMOTE_CODE_EXECUTION]: The skill's core synchronization and testing workflows clone remote repositories to a temporary directory and execute
npm installfollowed bynpm teston the retrieved source code. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes data from external repositories.
- Ingestion points: The skill reads
package.jsoncontent andCLAUDE.mddocumentation files from various repositories via the GitHub API and clones repositories for local analysis (SKILL.md). - Boundary markers: None identified. The skill does not implement specific delimiters or instructions to ignore embedded prompts within the retrieved file contents.
- Capability inventory: The skill possesses high-privilege capabilities including arbitrary shell command execution (
Bash), repository creation (mcp__github__create_repository), and file modification (mcp__github__push_files). - Sanitization: There is no evidence of sanitization, validation, or escaping of the content retrieved from remote repositories before it is processed or used to influence subsequent automated tasks.
Audit Metadata