dx-devops-work-item-manage
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs such as work item subjects, descriptions, and commit messages, which are interpolated into shell commands for the
sfandgitCLIs. This establishes a surface for potential command injection if the agent does not properly escape these inputs during execution. - Ingestion points: User-supplied values for fields like
--subject,--description,--status, and git commit messages (-m) inSKILL.mdPhase 2. - Boundary markers: The skill uses double quotes around placeholders (e.g.,
"<subject>") but lacks explicit instructions for the agent to perform strict escaping or validation of shell-sensitive characters. - Capability inventory: The skill uses subprocess execution for
sf,git, andjqcommands as defined in thecliToolsmetadata andSKILL.mdworkflows. - Sanitization: No specific sanitization or filtering logic is provided to the agent to handle potentially malicious shell syntax within the user-provided data fields.
Audit Metadata