github-profile-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external GitHub profiles (bios, repositories, and activity). This presents a surface for indirect prompt injection where an attacker could place instructions in their profile to influence the agent's behavior.
- Ingestion points: Data retrieved through the
strale_github_user_profiletool. - Capability inventory: The skill is limited to research and synthesis; no capabilities for file modification, command execution, or network exfiltration outside the provided tool gateway were identified.
- Boundary markers: None explicitly defined in the instructions to separate untrusted data from system prompts.
- Sanitization: No specific data sanitization or filtering logic is present in the skill instructions.
- [SAFE]: All identified tools and capabilities (
sandbase_describe_tool,sandbase_call_tool,strale_github_user_profile) are resources associated with the vendor 'sandbaseai'. Their use for read-only research is consistent with the stated purpose of the skill.
Audit Metadata