discover-tasks

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, attacker-controllable sources including GitHub issues, GitLab issues, and pull request titles and bodies. This content is processed by the agent to rank and present tasks, creating a surface for indirect prompt injection where malicious instructions in an issue body could attempt to influence the agent's behavior.
  • Ingestion points: External data is ingested via gh issue list, glab issue list, gh pr list, and local markdown files (PLAN.md, tasks.md, TODO.md).
  • Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings when processing the body of issues or PRs.
  • Capability inventory: The skill has access to shell execution via Bash (tools: gh, glab, git, grep), file reading (Read), and user interaction (AskUserQuestion).
  • Sanitization: The skill does not perform sanitization, escaping, or validation of the text content retrieved from external issue trackers before presenting it to the agent or the user.
  • [COMMAND_EXECUTION]: The skill constructs shell commands using variables such as $PROJECT_NUMBER, $OWNER, and $TASK_ID which are derived from external policy configurations and issue metadata. While these are often numeric or simple strings, a lack of strict validation could allow for command injection if the source data is compromised.
  • Evidence: The command gh project item-list "$PROJECT_NUMBER" --owner "$OWNER" in Phase 2 uses shell interpolation for parameters fetched from the policy object.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:15 AM
Security Audit — agent-trust-hub — discover-tasks