github-cache-hygiene
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing shell commands for gitcrawl, gh, and octopool. It instructs the agent to use these tools for discovery, metadata retrieval, and authorized writes to GitHub.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (GitHub issues, pull requests, comments, and diffs) which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: External data is ingested via gitcrawl (search/threads) and gh (issue view, pr view, pr diff, run list) in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore directives embedded in the ingested data.
- Capability inventory: The agent has the capability to execute shell commands (gitcrawl, gh, octopool) and perform writes to GitHub repositories as described in SKILL.md.
- Sanitization: There is no evidence of sanitization or validation of the content retrieved from GitHub before it is processed by the agent.
Audit Metadata