step-by-step
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a formatting style for step-by-step guides and includes instructions that promote safe secret management, such as explicitly telling users not to paste secrets into the chat.
- [SAFE]: The instructions recommend using secure methods for handling sensitive data, such as the
gh secret setcommand and theread -sshell flag, to prevent secrets from being printed or stored in logs. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to read information from environment files like
.envand GitHub workflow files. While this creates an ingestion point for untrusted data, the instructions focus on identifying metadata for user guidance rather than executing code or exfiltrating data, and the skill includes mitigation steps for secret handling.
Audit Metadata