dx-devops-work-item-manage

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs such as work item subjects, descriptions, and commit messages, which are interpolated into shell commands for the sf and git CLIs. This establishes a surface for potential command injection if the agent does not properly escape these inputs during execution.
  • Ingestion points: User-supplied values for fields like --subject, --description, --status, and git commit messages (-m) in SKILL.md Phase 2.
  • Boundary markers: The skill uses double quotes around placeholders (e.g., "<subject>") but lacks explicit instructions for the agent to perform strict escaping or validation of shell-sensitive characters.
  • Capability inventory: The skill uses subprocess execution for sf, git, and jq commands as defined in the cliTools metadata and SKILL.md workflows.
  • Sanitization: No specific sanitization or filtering logic is provided to the agent to handle potentially malicious shell syntax within the user-provided data fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:49 AM
Security Audit — agent-trust-hub — dx-devops-work-item-manage