github-multi-repo
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashfunction to execute a wide variety of shell commands, includinggh(GitHub CLI),git,npm, andjq. These commands are used to clone repositories, update dependencies, run tests, and create pull requests across multiple projects. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, specifically GitHub repositories, which creates a surface where malicious instructions embedded in code or documentation could influence the agent's behavior.
- Ingestion points: The skill fetches
package.jsonandCLAUDE.mdfiles from multiple GitHub repositories usinggh apiand theReadfunction. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions found within the ingested file content.
- Capability inventory: The skill possesses broad capabilities, including arbitrary command execution via
Bashand the ability to modify repositories via the GitHub API. - Sanitization: Content is decoded for processing but does not undergo sanitization or filtering to remove potential prompt injection attempts.
- [DYNAMIC_EXECUTION]: The skill dynamically constructs and executes shell scripts to automate tasks across multiple repositories.
- Evidence: Multiple
Bashblocks use loops and variable interpolation to clone, modify, and push changes to repositories determined at runtime based on discovery or user input.
Audit Metadata