triage
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Uses the GitHub CLI (
gh) to perform repository management tasks, including listing open issues and modifying issue labels. - [PROMPT_INJECTION]: The skill processes untrusted data from GitHub issue bodies and comments. This creates an indirect prompt injection surface where a malicious issue could attempt to influence the agent's triage recommendations or logic. However, the skill mitigates this by instructing the agent to follow a specific state machine and vocabulary, and to wait for maintainer direction before applying changes.
- [EXTERNAL_DOWNLOADS]: References an external dependency
/cba-searching, which is identified as an installed skill used to verify existing capabilities in the open-source ecosystem.
Audit Metadata