wizard
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates bash scripts and provides instructions to make them executable using
chmod +x. This is an intended function for creating runnable utility scripts. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes local repository files to determine setup stages, creating a potential surface for indirect instructions.
- Ingestion points: Data is ingested from
.env,.env.example,README, and GitHub workflow files in the local repository (SKILL.md). - Boundary markers: Absent; no explicit delimiters are used to isolate the ingested repository content during the scoping phase.
- Capability inventory: The generated script is capable of writing to the local filesystem and managing GitHub repository secrets using the
ghCLI (template.sh). - Sanitization: Absent; the process relies on the agent's static code verification and a human-in-the-loop review before the script is executed.
- [DATA_EXFILTRATION]: The generated setup scripts include functionality to upload credentials to GitHub Actions secrets via the
ghCLI. This interaction with GitHub's official service is the intended purpose of the skill's secret management feature.
Audit Metadata