discover-tasks
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, attacker-controllable sources including GitHub issues, GitLab issues, and pull request titles and bodies. This content is processed by the agent to rank and present tasks, creating a surface for indirect prompt injection where malicious instructions in an issue body could attempt to influence the agent's behavior.
- Ingestion points: External data is ingested via
gh issue list,glab issue list,gh pr list, and local markdown files (PLAN.md,tasks.md,TODO.md). - Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings when processing the body of issues or PRs.
- Capability inventory: The skill has access to shell execution via
Bash(tools: gh, glab, git, grep), file reading (Read), and user interaction (AskUserQuestion). - Sanitization: The skill does not perform sanitization, escaping, or validation of the text content retrieved from external issue trackers before presenting it to the agent or the user.
- [COMMAND_EXECUTION]: The skill constructs shell commands using variables such as
$PROJECT_NUMBER,$OWNER, and$TASK_IDwhich are derived from external policy configurations and issue metadata. While these are often numeric or simple strings, a lack of strict validation could allow for command injection if the source data is compromised. - Evidence: The command
gh project item-list "$PROJECT_NUMBER" --owner "$OWNER"in Phase 2 uses shell interpolation for parameters fetched from thepolicyobject.
Audit Metadata