spike-recommend

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the GitHub CLI (gh) to create and edit issues. This involves executing shell commands such as gh issue edit <N> --title "<title>" --body-file "$BRIEF_FILE" to perform its primary function.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface (Category 8) because it ingests and processes untrusted data from external sources.\n
  • Ingestion points: Fetches issue titles, descriptions, and comments from Linear and GitHub via MCP tools and the gh CLI (SKILL.md).\n
  • Boundary markers: The skill lacks explicit instructions to treat the ingested issue content as untrusted or to ignore any malicious instructions embedded within that content.\n
  • Capability inventory: The skill has the ability to write back to issue trackers, create local files in ./issue-briefs/, and send notifications via Slack.\n
  • Sanitization: There is no evidence of sanitization, filtering, or escaping applied to the fetched issue data before it is interpolated into the prompt logic for brief generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM