gitea-pagerank-workflow
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions involve the installation of the 'tea' CLI and the local compilation of the 'gitea-robot' tool from the vendor's repository.
- [COMMAND_EXECUTION]: Leverages shell commands involving 'git', 'tea', and 'gitea-robot' to automate the development lifecycle.
- [DATA_EXFILTRATION]: Performs API requests to 'git.terraphim.cloud'. It utilizes the 1Password CLI for secure credential management, reducing the risk of token exposure.
- [PROMPT_INJECTION]: Susceptible to indirect prompt injection (Category 8) via Gitea issue comments and notifications. 1. Ingestion points: Gitea API endpoints for comments and notifications accessed in 'references/agent-coordination.md'. 2. Boundary markers: None; the instructions do not specify delimiters to isolate external input. 3. Capability inventory: Significant, allowing file system changes via git and issue modification via tea CLI. 4. Sanitization: Absent; the skill does not outline procedures for validating or sanitizing data from external comments.
Audit Metadata