git-workflows
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The github_workflow_fix workflow identifies and processes external data which could contain adversarial content.
- Ingestion points: The skill retrieves GitHub Action job logs using
gh run view <run-id> --log-failedin references/source-commands.md. - Boundary markers: Instructions do not specify boundary markers or delimiters for the ingested log content.
- Capability inventory: The skill is capable of executing
git push,gh pr create, and modifying files within agit worktreeas defined in references/source-commands.md. - Sanitization: There is no evidence of sanitization or filtering applied to the logs before they are analyzed for root-cause diagnosis and automated fixes.
- [COMMAND_EXECUTION]: The skill utilizes several CLI tools to perform its core functions, including git, GitHub CLI, and Node.js utilities.
- Evidence: Executes
gitfor branch management,ghfor releases and workflow management, andnpx bumppfor versioning in references/source-commands.md. - Safety context: The skill's execution rules in SKILL.md require explicit user confirmation before any destructive or external side effects (like push or release) are performed.
- [EXTERNAL_DOWNLOADS]: The integrity check workflow performs network operations to verify resource availability.
- Evidence: Uses
curl -sIto validate icon URLs hosted on img.jsdelivr.com (referencing LobeHub repository content) in references/source-commands.md. - Context: These network operations are limited to HTTP HEAD requests for status code verification.
Audit Metadata