github-multi-repo

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash function to execute a wide variety of shell commands, including gh (GitHub CLI), git, npm, and jq. These commands are used to clone repositories, update dependencies, run tests, and create pull requests across multiple projects.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, specifically GitHub repositories, which creates a surface where malicious instructions embedded in code or documentation could influence the agent's behavior.
  • Ingestion points: The skill fetches package.json and CLAUDE.md files from multiple GitHub repositories using gh api and the Read function.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions found within the ingested file content.
  • Capability inventory: The skill possesses broad capabilities, including arbitrary command execution via Bash and the ability to modify repositories via the GitHub API.
  • Sanitization: Content is decoded for processing but does not undergo sanitization or filtering to remove potential prompt injection attempts.
  • [DYNAMIC_EXECUTION]: The skill dynamically constructs and executes shell scripts to automate tasks across multiple repositories.
  • Evidence: Multiple Bash blocks use loops and variable interpolation to clone, modify, and push changes to repositories determined at runtime based on discovery or user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — github-multi-repo