issue-tracker
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external GitHub issues, comments, and discussions to generate reports and infer action items.
- Ingestion points: External content is fetched from the GitHub API via specialized tools (e.g.,
mcp_github_github_issue_read,mcp_github_github_search_issues). - Boundary markers: The instructions lack explicit directives for the agent to treat external issue content as untrusted or to disregard potential instructions embedded within the text.
- Capability inventory: The skill possesses the ability to write Markdown and HTML files to the local workspace and perform state-changing operations on GitHub, such as posting comments and modifying issue statuses.
- Sanitization: No specific sanitization or validation steps are outlined for handling the external text before it is rendered into reports or used for decision-making.
Audit Metadata