launch
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from GitHub Pull Requests (titles, labels, and descriptions) which are controlled by external users. This data is processed and aggregated into reports, creating a surface for indirect prompt injection if the output is consumed by other LLM-based agents.
- Ingestion points: PR metadata fetched via the
ghCLI inscripts/generate-report.js. - Boundary markers: The
scripts/generate-report.jsscript includes anescapeHtmlfunction to sanitize PR titles before including them in HTML templates. - Capability inventory: The skill can write files to the local system (
fs.writeFileSync) and execute system commands (execFileSync, shell scripts). - Sanitization: Active HTML escaping is used to prevent XSS and direct injection in the generated report artifacts.
- [COMMAND_EXECUTION]: The skill uses local command execution to interact with the environment and generate deliverables.
scripts/generate-report.jsexecutes the GitHub CLI (gh) to retrieve data.scripts/html-to-pdf.shinvokes local browsers (google-chrome,chromium) and conversion tools (wkhtmltopdf) to export reports.scripts/puppeteer-pdf.jsusespuppeteerto launch a headless browser for rendering.- [EXTERNAL_DOWNLOADS]: The report generation template (
templates/client-report.html) fetches thechart.jslibrary fromcdn.jsdelivr.net. This is a well-known and trusted Content Delivery Network service.
Audit Metadata