github-profile-architect

Warn

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to dynamically generate and execute Python scripts locally to create SVG assets and modify the repository's README file.- [COMMAND_EXECUTION]: The skill establishes persistence by creating a GitHub Action workflow configured to run on a cron schedule for automated content updates.- [EXTERNAL_DOWNLOADS]: The skill fetches data from several third-party services and user-defined RSS feeds to populate profile widgets and blog lists.- [PROMPT_INJECTION]: The RSS blog fetcher ingests untrusted content from an external XML feed and injects it into the markdown without formal sanitization, creating an indirect prompt injection surface.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 10:17 PM