ensure-epic-github-issue

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on shell command interpolation to interact with the GitHub CLI (gh). Variables extracted from local markdown files, such as EPIC_TITLE, EPIC_STATUS, and EPIC_PRIORITY, are passed as arguments to gh issue create and gh project item-add. While these variables are enclosed in double quotes in the instructions, the lack of explicit sanitization of input data from EPIC_FILE_PATH could lead to command-line argument manipulation if the input contains malicious shell characters.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted markdown content.
  • Ingestion points: Untrusted data enters the agent context via the epic markdown file specified by EPIC_FILE_PATH (SKILL.md, Step E1) and the project.yml configuration file.
  • Boundary markers: There are no boundary markers or delimiters used to separate the extracted markdown content from the instructions passed to the GitHub CLI.
  • Capability inventory: The skill has the capability to write to the repository by creating issues and adding items to GitHub Project boards using the gh tool.
  • Sanitization: The skill does not perform escaping or validation of the markdown content (e.g., the opening paragraph or frontmatter fields) before interpolating it into the body or title of the generated GitHub issue.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — ensure-epic-github-issue