assayer
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection vulnerability through data ingestion. The skill reads content from the
## Ideasection of a GitHub issue and passes it as{idea-text}to multiple sub-agents (e.g., Market Scout, Feasibility Assessor). - Ingestion points:
SKILL.mdfetches the issue body using thegh issue viewcommand. - Boundary markers: No delimiters or "ignore embedded instructions" warnings are present. The untrusted
{idea-text}is directly interpolated into prompts. - Capability inventory: The skill uses
gh issue editto modify issue labels/content andgit pushto create and modify repository branches. - Sanitization: No sanitization or escaping of the issue content is performed before it is processed by the sub-agents.
- [COMMAND_EXECUTION]: The skill executes various
gh(GitHub CLI) andgitcommands. While these are part of the intended functionality (claiming issues, creating branches, updating labels), they provide a capability surface that could be exploited if an attacker successfully injects malicious instructions into a GitHub issue processed by the skill.
Audit Metadata