github-agentic-workflows

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill documents patterns for agents that ingest untrusted data from GitHub Issues, Pull Requests, and comments.
  • Ingestion points: GitHub Issues, Pull Request content, and comments (SKILL.md).
  • Boundary markers: The documentation suggests using structured outputs and 'threat-detection' layers, though specific prompt delimiters are not always shown in examples.
  • Capability inventory: High capabilities including file system access (edit, create), shell execution (bash), and repository management (github tools) (SKILL.md).
  • Sanitization: Emphasizes a 'Safe Outputs' architecture and 'threat-detection' scanning to sanitize AI-generated actions.
  • [COMMAND_EXECUTION]: Describes a bash toolset that allows the agent to execute shell commands such as npm and git within the workflow environment (SKILL.md).
  • [EXTERNAL_DOWNLOADS]: Mentions the installation of the github/gh-aw CLI extension and references external templates from the github organization (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 11:07 PM