github-agentic-workflows
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages workflows that ingest and process untrusted data from repository events, such as issues, pull requests, and external content. It explicitly addresses this attack surface by documenting a robust security model that includes read-only tokens, mandatory safe-output artifacts, and AI-powered threat detection scans for proposed changes.
- [EXTERNAL_DOWNLOADS]: Fetches installation scripts and reference markdown files from the official GitHub Agentic Workflows repository on GitHub.
- [REMOTE_CODE_EXECUTION]: Includes procedures for downloading and executing the
gh-awextension installer script directly from its official GitHub source using shell pipes. - [COMMAND_EXECUTION]: Executes a local Node.js utility script (
find-gh-aw-targets.mjs) to discover workflow-related files and markers within the current workspace. - [COMMAND_EXECUTION]: Orchestrates the
gh-awcommand-line tool to perform repository initialization, secret bootstrapping, and workflow compilation.
Audit Metadata