github-workflow-automation
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (
gh) and Git to automate tasks such as issue creation, pull request reviews, and repository coordination. - [REMOTE_CODE_EXECUTION]: The skill executes remote code by invoking
npx ruv-swarmandnpx claude-flow@alpha. It also integrates theruvnet/swarm-actionGitHub Action into CI/CD pipelines. - [EXTERNAL_DOWNLOADS]: The skill depends on fetching vendor-provided packages and GitHub Actions at runtime for its core operations.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external GitHub events, which can potentially influence its automated decision-making and repository interactions.
- Ingestion points: Data is ingested through GitHub CLI outputs (
gh pr view,gh run view) within the automated workflows. - Boundary markers: The instructions do not define clear boundaries or 'ignore' instructions for the data being analyzed by the AI agents.
- Capability inventory: The skill can perform write operations on the repository, including posting comments and creating issues.
- Sanitization: There is no semantic sanitization of the processed data, relying instead on the structural parsing of JSON and shell command outputs.
Audit Metadata