shipped-issues

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts information from GitHub issue bodies to identify linked work items.
  • Ingestion points: Open GitHub issue bodies and the repository's CHANGELOG.md file.
  • Boundary markers: None explicitly used to delimit external data.
  • Capability inventory: Includes the ability to close GitHub issues and query internal status databases.
  • Sanitization: The skill employs regex validation (W-\d{6,9}) to ensure that only properly formatted work item identifiers are processed from issue bodies.
  • Mitigation: A mandatory user confirmation step ensures that no issues are closed without human review of the automated findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:07 AM
Security Audit — agent-trust-hub — shipped-issues