project-crank-engine
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses several Git and GitHub CLI commands (
git rev-parse,git log,git status,git stash,gh pr list) to gather project status evidence. These are standard development tools and are used here for monitoring purposes. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from sprint boards and GitHub PRs to determine project completion. It lacks explicit boundary markers or sanitization for this untrusted data before it is interpolated into decision-making prompts.
- Ingestion points: External sprint board metrics and GitHub PR states are ingested via
{{done_metric_query}}and command outputs inreferences/prompt-templates.md. - Boundary markers: None identified in the prompt templates to distinguish between instructions and ingested data.
- Capability inventory: The skill uses
subprocess(viascripts/render_crank_prompt.py) and shell commands for repo/sprint status checks. - Sanitization: No explicit sanitization or validation of the ingested strings from the sprint board or GitHub API is present.
Audit Metadata