github-agentic-workflows

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill manages workflows that ingest and process untrusted data from repository events, such as issues, pull requests, and external content. It explicitly addresses this attack surface by documenting a robust security model that includes read-only tokens, mandatory safe-output artifacts, and AI-powered threat detection scans for proposed changes.
  • [EXTERNAL_DOWNLOADS]: Fetches installation scripts and reference markdown files from the official GitHub Agentic Workflows repository on GitHub.
  • [REMOTE_CODE_EXECUTION]: Includes procedures for downloading and executing the gh-aw extension installer script directly from its official GitHub source using shell pipes.
  • [COMMAND_EXECUTION]: Executes a local Node.js utility script (find-gh-aw-targets.mjs) to discover workflow-related files and markers within the current workspace.
  • [COMMAND_EXECUTION]: Orchestrates the gh-aw command-line tool to perform repository initialization, secret bootstrapping, and workflow compilation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:54 PM
Security Audit — agent-trust-hub — github-agentic-workflows