issues
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read, analyze, and act upon external data from GitHub issue bodies and comments, which are untrusted sources that could contain malicious instructions.
- Ingestion points: The skill uses
gh issue viewandgh issue list(referenced inSKILL.mdandreferences/create.md) to pull external content into the agent's context for processing. - Boundary markers: While the skill uses structured markdown templates to organize its output, there are no explicit instructions or delimiters used when interpolating external issue content to prevent the agent from following instructions embedded within that content.
- Capability inventory: The skill has the capability to execute shell commands via
gh(e.g.,gh issue edit,gh issue create) andgit(e.g.,git worktree add), and it orchestrates other execution-heavy skills likefix-itanddiagnose-bugbased on the processed issue data. - Sanitization: The instructions do not specify any sanitization, filtering, or escaping of the data retrieved from GitHub before it is used to generate implementation plans or draft further issues.
- [COMMAND_EXECUTION]: The skill frequently uses system command-line tools to perform its tasks.
- Evidence: The skill utilizes
gh(GitHub CLI) for issue management andgitfor workspace management (e.g.,git worktree add,git status). These are legitimate uses for the skill's purpose but represent the primary mechanism for potential impact if a prompt injection occurs.
Audit Metadata