github-star-manager

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified. Untrusted data from GitHub READMEs and external URLs is ingested in scripts/star_tracker.py and SKILL.md. Boundary markers and sanitization are absent, which could allow malicious repository content to influence agent actions such as starring or unstarring repositories.
  • [COMMAND_EXECUTION]: The skill executes local commands using the GitHub CLI and system utilities for repository management and dashboard viewing. These operations are user-triggered and the skill includes confirmation prompts for destructive actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 07:18 AM