glyph
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from the GitHub CLI (
gh) to create triage reports. This represents a potential indirect prompt injection surface that the skill correctly addresses through specific safety instructions.\n - Ingestion points: Data retrieved via
gh issue listandgh pr listis used to populatetemplates/triage.html.\n - Boundary markers: The agent is explicitly instructed to store data as a Base64 blob and use an
escapeHtmlfunction for rendering to prevent structural injection into the HTML DOM.\n - Capability inventory: The skill is restricted to a minimal set of tools (
Read,Grep,Glob), reducing the impact of any potential data-driven attack.\n - Sanitization: Robust sanitization logic (Base64 encoding and HTML escaping) is mandated in both the skill instructions and the provided templates.\n- [OBFUSCATION]: The
templates/triage.htmlfile contains a Base64-encoded string. Analysis shows this is a design feature for safe data handling and contains only benign example content, posing no security risk.\n- [DATA_EXPOSURE]: Documentation links point to the verified vendor domainorchestkit.yonyon.ai. No sensitive local information is transmitted to external endpoints.
Audit Metadata