engineer
Warn
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill dynamically identifies and executes shell commands for testing, linting, and static analysis by reading local project configuration files such as
package.json,composer.json,Makefile, orCLAUDE.md. This behavior relies on the integrity of the project files; if an attacker can modify these files (e.g., in a malicious repository), they can achieve arbitrary command execution when the agent attempts to run automated gates. - [PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issue bodies using the
gh issue viewcommand. This content is then used to drive the behavior of the orchestrator and sub-agents (Implementors, Test Smith, Security Auditor). There are no explicit boundary markers or instructions to ignore embedded malicious prompts within the issue content, making it susceptible to indirect prompt injection. - Ingestion points: Issue content read via
gh issue view {issue-number}in the 'Read Issue' phase. - Boundary markers: Absent. The skill does not implement delimiters or specific instructions to isolate the issue body from the agent's operational logic.
- Capability inventory: The agent has extensive capabilities including file writing, shell command execution, Git operations (commit, push, rebase), and GitHub CLI operations (PR creation, issue editing).
- Sanitization: Basic sanitization is performed only for the
idea-slug(lowercase and hyphenation) used for branch naming. - [COMMAND_EXECUTION]: The skill constructs complex shell commands for the GitHub CLI (
gh pr create,gh issue edit) using string interpolation of potentially untrusted data like issue titles and agent-generated summaries. While it uses heredocs for the PR body, other parameters like--titleare interpolated directly, which could lead to argument injection if titles contain shell metacharacters.
Audit Metadata