best-practices-github-ticket
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a shell script
scripts/gh-ticket-tools.shthat acts as a wrapper for the GitHub CLI (gh), enabling the agent to perform issue lifecycle operations such as leasing, commenting, and closing tickets. - [EXTERNAL_DOWNLOADS]: The
sanity.shscript dynamically fetches thepyyamllibrary usinguv run.pyyamlis a widely used and trusted package for YAML processing. - [PROMPT_INJECTION]: The skill ingests untrusted content from GitHub issue bodies, which constitutes a surface for indirect prompt injection. \n
- Ingestion points: GitHub issue bodies are retrieved via
gh issue viewand processed by a Python parser inscripts/gh-ticket-tools.sh.\n - Boundary markers: No explicit boundary markers are used to isolate instructions within the issue content.\n
- Capability inventory: The skill has the ability to modify GitHub issues and perform Git operations using the helper scripts. \n
- Sanitization: The Python parser employs a validation function,
clean_fragment, which effectively prevents path traversal attacks and restricts the extraction to relative repository paths.
Audit Metadata