shipped-issues

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the GitHub CLI (gh) and Salesforce CLI (sf). These operations are used to fetch release notes, list issues, and query the status of internal work items (ADM_Work__c). All commands are targeted at the forcedotcom/apex-language-support repository or use a pre-defined local alias (gus) for authentication.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for untrusted data as it reads and processes GitHub issue bodies and release notes. However, it mitigates potential risks by using specific regex patterns (e.g., W-\d{6,9}) to extract identifiers and strictly requires the user to review a generated table and provide explicit confirmation before any issues are closed.
  • [DATA_EXPOSURE]: The workflow utilizes temporary local files (/tmp/shipped-releases.json, /tmp/shipped-changelog.md, /tmp/shipped-issues.json) to store and aggregate data during the execution process. This data consists of public repository information and metadata from internal work tracking items.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:05 AM
Security Audit — agent-trust-hub — shipped-issues