assayer

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection vulnerability through data ingestion. The skill reads content from the ## Idea section of a GitHub issue and passes it as {idea-text} to multiple sub-agents (e.g., Market Scout, Feasibility Assessor).
  • Ingestion points: SKILL.md fetches the issue body using the gh issue view command.
  • Boundary markers: No delimiters or "ignore embedded instructions" warnings are present. The untrusted {idea-text} is directly interpolated into prompts.
  • Capability inventory: The skill uses gh issue edit to modify issue labels/content and git push to create and modify repository branches.
  • Sanitization: No sanitization or escaping of the issue content is performed before it is processed by the sub-agents.
  • [COMMAND_EXECUTION]: The skill executes various gh (GitHub CLI) and git commands. While these are part of the intended functionality (claiming issues, creating branches, updating labels), they provide a capability surface that could be exploited if an attacker successfully injects malicious instructions into a GitHub issue processed by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 02:02 PM