github-workflow-automation

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources such as GitHub Pull Requests, issues, and logs, which presents a surface for indirect injection attacks.
  • Ingestion points: External data enters the agent's context through commands in SKILL.md such as gh pr view, gh run view, and npx ruv-swarm actions detect-changes.
  • Boundary markers: The instructions do not define explicit delimiters or instructions to ignore potentially malicious content embedded within the ingested data.
  • Capability inventory: The skill has the capability to write to the local filesystem (generating .github/workflows/ files), execute shell commands via npx, and perform network operations via the GitHub CLI (gh).
  • Sanitization: There is no evidence of sanitization or validation performed on the external content before it is processed by the AI swarm agents.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution to perform its primary tasks, including generating workflows, analyzing failures, and managing repository states.
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes vendor-provided tools (ruv-swarm, claude-flow@alpha) from the npm registry at runtime using npx.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — github-workflow-automation