dev-ai-coding-metrics

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/extract_github_events.py script fetches pull-request and commit telemetry from the official GitHub API (api.github.com). This is a legitimate and documented feature for metric collection and targets a trusted domain.
  • [CREDENTIALS_SAFE]: The skill implements secure credential handling by retrieving the GITHUB_TOKEN from an environment variable in scripts/extract_github_events.py, adhering to security best practices for secret management.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external content via the GitHub API and local JSON metric files. While this establishes an ingestion surface, the risk is minimal as the scripts (roi_calculator.py and extract_github_events.py) perform bounded calculations and formatting without dangerous capabilities such as shell command execution or dynamic code evaluation on the input data. Boundary markers are maintained through the use of structured data formats.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — dev-ai-coding-metrics