maintainer-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill establishes a robust process for repository maintenance, including recording git state before mutations, ensuring fast-forward pulls on clean branches, and preserving local work. It requires established root causes and regression coverage before landing any changes.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, specifically GitHub issues and pull requests. This represents an inherent indirect prompt injection surface. The skill mitigates this risk through explicit instructions to treat contributor contributions as proposals rather than accepted designs, requiring independent reproduction of symptoms, and mandating that agents verify permissions before performing sensitive network or filesystem operations.
Audit Metadata