create-epic

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple system commands, including gh (GitHub CLI) for issue management, git for repository metadata, and python -c for parsing configuration files. It also includes a tracker_call_with_retry helper in references/resolve-platform.sh that wraps arbitrary command execution with retry logic.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with GitHub and Jira APIs via the gh CLI and the sync-jira-epic tool to create and update project tracker issues. While these are necessary for the skill's purpose, they involve sending user-controlled data to external services.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present where user-supplied enhancement details (title, goal, and stories) are interpolated into markdown templates and then passed to shell commands for issue creation. 1. Ingestion points: User-provided feature descriptions processed in SKILL.md. 2. Boundary markers: Absent from the interpolation templates. 3. Capability inventory: File system writes to docs/prd/, network operations via gh CLI, and calls to the sync-jira-epic implementation tool. 4. Sanitization: The skill does not perform escaping, validation, or sanitization of the user-provided content before it is used in tracker mutation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — create-epic