ensure-epic-github-issue
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on shell command interpolation to interact with the GitHub CLI (
gh). Variables extracted from local markdown files, such asEPIC_TITLE,EPIC_STATUS, andEPIC_PRIORITY, are passed as arguments togh issue createandgh project item-add. While these variables are enclosed in double quotes in the instructions, the lack of explicit sanitization of input data fromEPIC_FILE_PATHcould lead to command-line argument manipulation if the input contains malicious shell characters. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted markdown content.
- Ingestion points: Untrusted data enters the agent context via the epic markdown file specified by
EPIC_FILE_PATH(SKILL.md, Step E1) and theproject.ymlconfiguration file. - Boundary markers: There are no boundary markers or delimiters used to separate the extracted markdown content from the instructions passed to the GitHub CLI.
- Capability inventory: The skill has the capability to write to the repository by creating issues and adding items to GitHub Project boards using the
ghtool. - Sanitization: The skill does not perform escaping or validation of the markdown content (e.g., the opening paragraph or frontmatter fields) before interpolating it into the body or title of the generated GitHub issue.
Audit Metadata