github-issue
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issues and projects, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The agent reads external data using commands like
gh issue view,gh issue list, andgh project item-listas defined inreferences/gh-commands.md. - Boundary markers: The skill includes a
HARD-GATEinstruction inSKILL.mdthat explicitly requires direct user authorization for state-changing actions, serving as a manual security boundary. - Capability inventory: The skill possesses capabilities to create, edit, and close issues, as well as modify project boards using
gh issuecommands andgh api graphql. - Sanitization: The instructions do not specify any sanitization or validation steps for the data retrieved from GitHub before it is analyzed by the agent.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the GitHub CLI tool.
- Evidence:
references/gh-commands.mdprovides a reference ofghCLI commands and GraphQL queries that the agent uses to interact with repository data and project boards.
Audit Metadata