skills/simota/agent-skills/launch/Gen Agent Trust Hub

launch

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from GitHub Pull Requests (titles, labels, and descriptions) which are controlled by external users. This data is processed and aggregated into reports, creating a surface for indirect prompt injection if the output is consumed by other LLM-based agents.
  • Ingestion points: PR metadata fetched via the gh CLI in scripts/generate-report.js.
  • Boundary markers: The scripts/generate-report.js script includes an escapeHtml function to sanitize PR titles before including them in HTML templates.
  • Capability inventory: The skill can write files to the local system (fs.writeFileSync) and execute system commands (execFileSync, shell scripts).
  • Sanitization: Active HTML escaping is used to prevent XSS and direct injection in the generated report artifacts.
  • [COMMAND_EXECUTION]: The skill uses local command execution to interact with the environment and generate deliverables.
  • scripts/generate-report.js executes the GitHub CLI (gh) to retrieve data.
  • scripts/html-to-pdf.sh invokes local browsers (google-chrome, chromium) and conversion tools (wkhtmltopdf) to export reports.
  • scripts/puppeteer-pdf.js uses puppeteer to launch a headless browser for rendering.
  • [EXTERNAL_DOWNLOADS]: The report generation template (templates/client-report.html) fetches the chart.js library from cdn.jsdelivr.net. This is a well-known and trusted Content Delivery Network service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — launch