maintainer-orchestrator
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing untrusted data from external sources and using it to drive highly privileged repository actions.\n
- Ingestion points: The orchestrator reads and processes content from GitHub issues, pull requests, and discovery scans as defined in
SKILL.md.\n - Boundary markers: There are no instructions to use specific delimiters or to ignore potential instructions embedded within the external issue or pull request descriptions.\n
- Capability inventory: The skill is authorized to perform sensitive actions including commits, pushes, pull request mutations, merges, and release publications across target repositories.\n
- Sanitization: The instructions lack requirements for sanitizing or validating external input before it influences the agent's decision-making process.
Audit Metadata