github-project-triage
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines and executes shell commands and local scripts to interact with GitHub and the local file system. It utilizes
ghCLI,git, andswift, along with custom scripts likegithub-activity.shand a local utility calledrepobarto perform triage, status checks, and repository management. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize untrusted content from GitHub issues and pull requests, which is a potential vector for indirect prompt injection. To mitigate this, the instructions explicitly direct the agent to treat project owner comments as authoritative routing instructions that override other signals, and it requires explicit user permission and verification before performing autonomous work. Ingestion points include issue and PR summaries and bodies across various GitHub repositories.
Audit Metadata