dev-ai-coding-metrics
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/extract_github_events.pyscript fetches pull-request and commit telemetry from the official GitHub API (api.github.com). This is a legitimate and documented feature for metric collection and targets a trusted domain. - [CREDENTIALS_SAFE]: The skill implements secure credential handling by retrieving the
GITHUB_TOKENfrom an environment variable inscripts/extract_github_events.py, adhering to security best practices for secret management. - [INDIRECT_PROMPT_INJECTION]: The skill processes external content via the GitHub API and local JSON metric files. While this establishes an ingestion surface, the risk is minimal as the scripts (
roi_calculator.pyandextract_github_events.py) perform bounded calculations and formatting without dangerous capabilities such as shell command execution or dynamic code evaluation on the input data. Boundary markers are maintained through the use of structured data formats.
Audit Metadata