best-practices-github-ticket

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell script scripts/gh-ticket-tools.sh that acts as a wrapper for the GitHub CLI (gh), enabling the agent to perform issue lifecycle operations such as leasing, commenting, and closing tickets.
  • [EXTERNAL_DOWNLOADS]: The sanity.sh script dynamically fetches the pyyaml library using uv run. pyyaml is a widely used and trusted package for YAML processing.
  • [PROMPT_INJECTION]: The skill ingests untrusted content from GitHub issue bodies, which constitutes a surface for indirect prompt injection. \n
  • Ingestion points: GitHub issue bodies are retrieved via gh issue view and processed by a Python parser in scripts/gh-ticket-tools.sh.\n
  • Boundary markers: No explicit boundary markers are used to isolate instructions within the issue content.\n
  • Capability inventory: The skill has the ability to modify GitHub issues and perform Git operations using the helper scripts. \n
  • Sanitization: The Python parser employs a validation function, clean_fragment, which effectively prevents path traversal attacks and restricts the extraction to relative repository paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — best-practices-github-ticket