outside-to-issue
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of a local script, scripts/transform-outside-to-issues.sh, to automate file transformations within the repository structure.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a pipeline for external data that could contain malicious instructions. 1. Ingestion points: Markdown files located in the ai-docs/reviews-pr-/outside/ directory. 2. Boundary markers: The skill generates issues using standard markdown headers (e.g., # Issue, ## Body) but does not include specific warnings or delimiters to prevent the agent from following instructions embedded in the review text. 3. Capability inventory: The skill has the ability to read from and write to the filesystem and execute shell and python scripts (such as resolve_pr_issues.py). 4. Sanitization: There is no evidence of input validation or character escaping to neutralize potential prompt injections within the review content during transformation.
Audit Metadata