outside-to-issue

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of a local script, scripts/transform-outside-to-issues.sh, to automate file transformations within the repository structure.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a pipeline for external data that could contain malicious instructions. 1. Ingestion points: Markdown files located in the ai-docs/reviews-pr-/outside/ directory. 2. Boundary markers: The skill generates issues using standard markdown headers (e.g., # Issue, ## Body) but does not include specific warnings or delimiters to prevent the agent from following instructions embedded in the review text. 3. Capability inventory: The skill has the ability to read from and write to the filesystem and execute shell and python scripts (such as resolve_pr_issues.py). 4. Sanitization: There is no evidence of input validation or character escaping to neutralize potential prompt injections within the review content during transformation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — outside-to-issue