premature-close-checker
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate issue management tasks using established tools.
- [COMMAND_EXECUTION]: Executes a local bash script for issue checking logic. The script path is based on the vendor's project structure ('fellowship-dev/pylot').
- [PROMPT_INJECTION]: The skill processes external data (GitHub issue content) to identify incomplete tasks. While this represents a surface for indirect prompt injection, the risk is inherent to the skill's primary function and no exploitable pattern was identified.
- [DATA_EXPOSURE]: Uses the GitHub CLI to view issue labels and status. These read operations are limited to the scope required for the task.
Audit Metadata