create-epic
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple system commands, including
gh(GitHub CLI) for issue management,gitfor repository metadata, andpython -cfor parsing configuration files. It also includes atracker_call_with_retryhelper inreferences/resolve-platform.shthat wraps arbitrary command execution with retry logic. - [EXTERNAL_DOWNLOADS]: The skill interacts with GitHub and Jira APIs via the
ghCLI and thesync-jira-epictool to create and update project tracker issues. While these are necessary for the skill's purpose, they involve sending user-controlled data to external services. - [PROMPT_INJECTION]: An indirect prompt injection surface is present where user-supplied enhancement details (title, goal, and stories) are interpolated into markdown templates and then passed to shell commands for issue creation. 1. Ingestion points: User-provided feature descriptions processed in
SKILL.md. 2. Boundary markers: Absent from the interpolation templates. 3. Capability inventory: File system writes todocs/prd/, network operations viaghCLI, and calls to thesync-jira-epicimplementation tool. 4. Sanitization: The skill does not perform escaping, validation, or sanitization of the user-provided content before it is used in tracker mutation commands.
Audit Metadata