maintainer-orchestrator

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing untrusted data from external sources and using it to drive highly privileged repository actions.\n
  • Ingestion points: The orchestrator reads and processes content from GitHub issues, pull requests, and discovery scans as defined in SKILL.md.\n
  • Boundary markers: There are no instructions to use specific delimiters or to ignore potential instructions embedded within the external issue or pull request descriptions.\n
  • Capability inventory: The skill is authorized to perform sensitive actions including commits, pushes, pull request mutations, merges, and release publications across target repositories.\n
  • Sanitization: The instructions lack requirements for sanitizing or validating external input before it influences the agent's decision-making process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 06:02 AM
Security Audit — agent-trust-hub — maintainer-orchestrator