github-workflow-automation
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources such as GitHub Pull Requests, issues, and logs, which presents a surface for indirect injection attacks.
- Ingestion points: External data enters the agent's context through commands in
SKILL.mdsuch asgh pr view,gh run view, andnpx ruv-swarm actions detect-changes. - Boundary markers: The instructions do not define explicit delimiters or instructions to ignore potentially malicious content embedded within the ingested data.
- Capability inventory: The skill has the capability to write to the local filesystem (generating
.github/workflows/files), execute shell commands vianpx, and perform network operations via the GitHub CLI (gh). - Sanitization: There is no evidence of sanitization or validation performed on the external content before it is processed by the AI swarm agents.
- [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution to perform its primary tasks, including generating workflows, analyzing failures, and managing repository states.
- [EXTERNAL_DOWNLOADS]: The skill downloads and executes vendor-provided tools (
ruv-swarm,claude-flow@alpha) from the npm registry at runtime usingnpx.
Audit Metadata