shipped-issues
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill extracts information from GitHub issue bodies to identify linked work items.
- Ingestion points: Open GitHub issue bodies and the repository's CHANGELOG.md file.
- Boundary markers: None explicitly used to delimit external data.
- Capability inventory: Includes the ability to close GitHub issues and query internal status databases.
- Sanitization: The skill employs regex validation (W-\d{6,9}) to ensure that only properly formatted work item identifiers are processed from issue bodies.
- Mitigation: A mandatory user confirmation step ensures that no issues are closed without human review of the automated findings.
Audit Metadata