skills/volcengine/openviking/github/Gen Agent Trust Hub

github

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external GitHub resources such as issues, pull requests, and workflow logs.\n
  • Ingestion points: Data is pulled into the environment through gh issue, gh pr, gh run, and gh api commands.\n
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat external content as untrusted data or to ignore embedded instructions.\n
  • Capability inventory: The skill has the capability to execute gh CLI commands and perform network operations via the GitHub API.\n
  • Sanitization: The skill does not implement specific sanitization or validation of the content retrieved from GitHub before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands using the GitHub CLI (gh) to perform repository management tasks.\n- [EXTERNAL_DOWNLOADS]: The skill configuration includes metadata for installing the official GitHub CLI tool via standard system package managers such as Homebrew (brew) and APT.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — github