github-star-manager
Pass
Audited by Gen Agent Trust Hub on Mar 7, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified. Untrusted data from GitHub READMEs and external URLs is ingested in
scripts/star_tracker.pyandSKILL.md. Boundary markers and sanitization are absent, which could allow malicious repository content to influence agent actions such as starring or unstarring repositories. - [COMMAND_EXECUTION]: The skill executes local commands using the GitHub CLI and system utilities for repository management and dashboard viewing. These operations are user-triggered and the skill includes confirmation prompts for destructive actions.
Audit Metadata