skills/devcxl/skills-zh/qa/Gen Agent Trust Hub

qa

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the gh command-line interface to programmatically create issues on GitHub based on user-provided descriptions.
  • [PROMPT_INJECTION]: The skill processes untrusted user input and incorporates information from local files (e.g., UBIQUITOUS_LANGUAGE.md) into issue reports. It lacks explicit boundary markers for these inputs and instructs the agent to submit issues without a final user review step, creating a potential surface for indirect prompt injection or the propagation of adversarial content to external repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 12:24 PM
Security Audit — agent-trust-hub — qa