gitea-pagerank-workflow

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions involve the installation of the 'tea' CLI and the local compilation of the 'gitea-robot' tool from the vendor's repository.
  • [COMMAND_EXECUTION]: Leverages shell commands involving 'git', 'tea', and 'gitea-robot' to automate the development lifecycle.
  • [DATA_EXFILTRATION]: Performs API requests to 'git.terraphim.cloud'. It utilizes the 1Password CLI for secure credential management, reducing the risk of token exposure.
  • [PROMPT_INJECTION]: Susceptible to indirect prompt injection (Category 8) via Gitea issue comments and notifications. 1. Ingestion points: Gitea API endpoints for comments and notifications accessed in 'references/agent-coordination.md'. 2. Boundary markers: None; the instructions do not specify delimiters to isolate external input. 3. Capability inventory: Significant, allowing file system changes via git and issue modification via tea CLI. 4. Sanitization: Absent; the skill does not outline procedures for validating or sanitizing data from external comments.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 11:56 AM
Security Audit — agent-trust-hub — gitea-pagerank-workflow