project-watchdog
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive shell command execution using
subprocess.Popento interact with external tools including theghCLI,git, anduv. It also executes custom automation commands defined within theregistry/projects.jsonconfiguration file. Additionally, theinstall-croncommand facilitates persistence by modifying the user's crontab to maintain the dispatch loop. - [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it ingests and processes untrusted data from GitHub issue bodies to drive automation logic.
- Ingestion points: Untrusted issue content is retrieved in
scripts/watchdog/registry.pyand parsed for directives inscripts/watchdog/issue_fields.py. - Boundary markers: Task generation logic in
scripts/watchdog/handlers.pyutilizes markdown headers and specific delimiters (e.g., '--- ticket body ---') to isolate untrusted external content from the agent's core instructions. - Capability inventory: The skill possesses broad execution capabilities, including arbitrary command invocation via
scripts/watchdog/core.py, file system access across configured worktrees, and GitHub issue mutation. - Sanitization: Input validation is handled in
scripts/watchdog/issue_fields.py, which includes therepo_relative_existing_pathfunction to prevent directory traversal by ensuring all referenced paths remain within the project worktree. - [DATA_EXFILTRATION]: The skill interacts with the GitHub API to update issues, post comments, and manage labels. While this is the intended functionality of the orchestration dispatcher, it involves the transmission of project state and metadata to an external cloud service.
Audit Metadata