github-author-context
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (e.g.,
gh,git,rg) and local scripts (e.g.,clawtributors) using placeholders for user-supplied data such as<login>,<name>, and<discord>. This creates a command injection vulnerability if the agent interpolates malicious strings into these shell commands without proper escaping. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub profiles, PR titles, and issue descriptions, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Data is fetched via
gh api,gh search, andgit logfrom public repositories and external users. - Boundary markers: No specific delimiters or "ignore embedded instructions" directives are provided to the agent for handling the ingested external content in
SKILL.md. - Capability inventory: The skill possesses capabilities for shell command execution, local script execution, and file reading within specific project directories (
~/Projects/maintainers/). - Sanitization: The skill lacks explicit instructions for sanitizing or escaping the data retrieved from GitHub before it is used in subsequent logic or presented to the user.
Audit Metadata