github-author-context

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (e.g., gh, git, rg) and local scripts (e.g., clawtributors) using placeholders for user-supplied data such as <login>, <name>, and <discord>. This creates a command injection vulnerability if the agent interpolates malicious strings into these shell commands without proper escaping.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub profiles, PR titles, and issue descriptions, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Data is fetched via gh api, gh search, and git log from public repositories and external users.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" directives are provided to the agent for handling the ingested external content in SKILL.md.
  • Capability inventory: The skill possesses capabilities for shell command execution, local script execution, and file reading within specific project directories (~/Projects/maintainers/).
  • Sanitization: The skill lacks explicit instructions for sanitizing or escaping the data retrieved from GitHub before it is used in subsequent logic or presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:26 PM
Security Audit — agent-trust-hub — github-author-context