skills/decisionnerd/dev-skills/issues/Gen Agent Trust Hub

issues

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read, analyze, and act upon external data from GitHub issue bodies and comments, which are untrusted sources that could contain malicious instructions.
  • Ingestion points: The skill uses gh issue view and gh issue list (referenced in SKILL.md and references/create.md) to pull external content into the agent's context for processing.
  • Boundary markers: While the skill uses structured markdown templates to organize its output, there are no explicit instructions or delimiters used when interpolating external issue content to prevent the agent from following instructions embedded within that content.
  • Capability inventory: The skill has the capability to execute shell commands via gh (e.g., gh issue edit, gh issue create) and git (e.g., git worktree add), and it orchestrates other execution-heavy skills like fix-it and diagnose-bug based on the processed issue data.
  • Sanitization: The instructions do not specify any sanitization, filtering, or escaping of the data retrieved from GitHub before it is used to generate implementation plans or draft further issues.
  • [COMMAND_EXECUTION]: The skill frequently uses system command-line tools to perform its tasks.
  • Evidence: The skill utilizes gh (GitHub CLI) for issue management and git for workspace management (e.g., git worktree add, git status). These are legitimate uses for the skill's purpose but represent the primary mechanism for potential impact if a prompt injection occurs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — issues