spike-recommend
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the GitHub CLI (
gh) to create and edit issues. This involves executing shell commands such asgh issue edit <N> --title "<title>" --body-file "$BRIEF_FILE"to perform its primary function.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface (Category 8) because it ingests and processes untrusted data from external sources.\n - Ingestion points: Fetches issue titles, descriptions, and comments from Linear and GitHub via MCP tools and the
ghCLI (SKILL.md).\n - Boundary markers: The skill lacks explicit instructions to treat the ingested issue content as untrusted or to ignore any malicious instructions embedded within that content.\n
- Capability inventory: The skill has the ability to write back to issue trackers, create local files in
./issue-briefs/, and send notifications via Slack.\n - Sanitization: There is no evidence of sanitization, filtering, or escaping applied to the fetched issue data before it is interpolated into the prompt logic for brief generation.
Audit Metadata