autopilot
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions to operate in an autonomous mode, explicitly directing the agent to bypass user confirmation for planning and execution phases ("不需要中途确认", "不需要中途展示计划").
- [PROMPT_INJECTION]: Employs authoritative language such as "CRITICAL" and "最高优先级" (Highest Priority) to enforce specific internal logic and loop execution patterns, mirroring directives used in prompt override attempts.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple points, including GitHub issue descriptions and web content (via
agent-browser), without defined boundary markers or input sanitization. This is coupled with a high-capability inventory that includes code modification, Git operations, and deployment via GitHub CLI, creating a surface where malicious external instructions could be autonomously processed. - [COMMAND_EXECUTION]: The workflow involves orchestrating shell commands for repository management (Git), deployment tasks (GitHub CLI), and general implementation/testing scripts.
- [DATA_EXFILTRATION]: The skill interacts with GitHub's official services using
gh-clito post implementation logs and evidence summaries to issues as part of its automated reporting workflow.
Audit Metadata