shipped-issues
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using the GitHub CLI (
gh) and Salesforce CLI (sf). These operations are used to fetch release notes, list issues, and query the status of internal work items (ADM_Work__c). All commands are targeted at theforcedotcom/apex-language-supportrepository or use a pre-defined local alias (gus) for authentication. - [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for untrusted data as it reads and processes GitHub issue bodies and release notes. However, it mitigates potential risks by using specific regex patterns (e.g.,
W-\d{6,9}) to extract identifiers and strictly requires the user to review a generated table and provide explicit confirmation before any issues are closed. - [DATA_EXPOSURE]: The workflow utilizes temporary local files (
/tmp/shipped-releases.json,/tmp/shipped-changelog.md,/tmp/shipped-issues.json) to store and aggregate data during the execution process. This data consists of public repository information and metadata from internal work tracking items.
Audit Metadata