github-profile-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external GitHub profiles (bios, repositories, and activity). This presents a surface for indirect prompt injection where an attacker could place instructions in their profile to influence the agent's behavior.
  • Ingestion points: Data retrieved through the strale_github_user_profile tool.
  • Capability inventory: The skill is limited to research and synthesis; no capabilities for file modification, command execution, or network exfiltration outside the provided tool gateway were identified.
  • Boundary markers: None explicitly defined in the instructions to separate untrusted data from system prompts.
  • Sanitization: No specific data sanitization or filtering logic is present in the skill instructions.
  • [SAFE]: All identified tools and capabilities (sandbase_describe_tool, sandbase_call_tool, strale_github_user_profile) are resources associated with the vendor 'sandbaseai'. Their use for read-only research is consistent with the stated purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — github-profile-research