github-workflow-automation

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) and Git to automate tasks such as issue creation, pull request reviews, and repository coordination.
  • [REMOTE_CODE_EXECUTION]: The skill executes remote code by invoking npx ruv-swarm and npx claude-flow@alpha. It also integrates the ruvnet/swarm-action GitHub Action into CI/CD pipelines.
  • [EXTERNAL_DOWNLOADS]: The skill depends on fetching vendor-provided packages and GitHub Actions at runtime for its core operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external GitHub events, which can potentially influence its automated decision-making and repository interactions.
  • Ingestion points: Data is ingested through GitHub CLI outputs (gh pr view, gh run view) within the automated workflows.
  • Boundary markers: The instructions do not define clear boundaries or 'ignore' instructions for the data being analyzed by the AI agents.
  • Capability inventory: The skill can perform write operations on the repository, including posting comments and creating issues.
  • Sanitization: There is no semantic sanitization of the processed data, relying instead on the structural parsing of JSON and shell command outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — github-workflow-automation