ci-sentinel

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub PRs and CI logs, creating an attack surface for indirect prompt injection. Ingestion points include fetching data using gh pr list and gh api. While it mentions a quarantine rule as a boundary marker, it lacks explicit sanitization. The agent has the capability to post comments to PRs and read repository files.
  • [EXTERNAL_DOWNLOADS]: The installation process involves fetching a GitHub Actions workflow file from the external OrchestKit repository.
  • [COMMAND_EXECUTION]: The skill performs shell operations using the Bash tool to execute GitHub CLI commands for repository management and PR interaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 AM
Security Audit — agent-trust-hub — ci-sentinel