plan
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the GitHub CLI via
gh issue createto publish generated task slices as issues. This behavior is documented and aligns with the skill's stated purpose of automating the transition from planning to execution. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests and processes untrusted data from the local codebase and documentation folder to inform its planning logic.
- Ingestion points: Reads content from
docs/CONTEXT.md,docs/adr/, and the general codebase. - Boundary markers: The instructions do not provide explicit delimiters or instructions to the agent to ignore potentially malicious embedded commands within the files it analyzes.
- Capability inventory: The skill possesses file-writing capabilities (creating and updating
.mdfiles in thedocs/directory) and shell command execution (gh issue create). - Sanitization: There are no mentioned filters or sanitization steps to validate content extracted from the codebase before it is interpolated into the agent's planning context or published as issues.
Audit Metadata