project-watchdog

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive shell command execution using subprocess.Popen to interact with external tools including the gh CLI, git, and uv. It also executes custom automation commands defined within the registry/projects.json configuration file. Additionally, the install-cron command facilitates persistence by modifying the user's crontab to maintain the dispatch loop.
  • [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it ingests and processes untrusted data from GitHub issue bodies to drive automation logic.
  • Ingestion points: Untrusted issue content is retrieved in scripts/watchdog/registry.py and parsed for directives in scripts/watchdog/issue_fields.py.
  • Boundary markers: Task generation logic in scripts/watchdog/handlers.py utilizes markdown headers and specific delimiters (e.g., '--- ticket body ---') to isolate untrusted external content from the agent's core instructions.
  • Capability inventory: The skill possesses broad execution capabilities, including arbitrary command invocation via scripts/watchdog/core.py, file system access across configured worktrees, and GitHub issue mutation.
  • Sanitization: Input validation is handled in scripts/watchdog/issue_fields.py, which includes the repo_relative_existing_path function to prevent directory traversal by ensuring all referenced paths remain within the project worktree.
  • [DATA_EXFILTRATION]: The skill interacts with the GitHub API to update issues, post comments, and manage labels. While this is the intended functionality of the orchestration dispatcher, it involves the transmission of project state and metadata to an external cloud service.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — project-watchdog