triage
Fail
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: HIGHINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub issues and pull requests, including bodies, comments, and code diffs.\n
- Ingestion points: External data enters the agent's context through the issue tracker in
SKILL.md, which explicitly reads issue bodies, comments, and PR diffs.\n - Boundary markers: The instructions lack boundary markers or warnings to treat external content as untrusted data rather than instructions.\n
- Capability inventory: The agent has capabilities to read and write files (e.g., within the
.out-of-scope/directory), interact with the GitHub API for issues and PRs, and execute shell commands via verification steps.\n - Sanitization: There is no mention of sanitizing or validating external content before processing.\n- [DYNAMIC_EXECUTION]: The skill instructions for pull request triage include a verification step that requires executing code provided by external contributors.\n
- Evidence:
SKILL.mdinstructs the agent to: "confirm the diff does what it claims — check it out, run the relevant tests or commands." This represents the execution of arbitrary code from an untrusted external source.\n- [COMMAND_EXECUTION]: The skill is directed to run tests or commands to verify pull requests, which involves executing shell commands against external, potentially malicious pull request code.
Recommendations
- AI detected serious security threats
Audit Metadata